mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-06 02:48:13 +00:00
test(e2e): declare coverage registry cells for project all-team-models tests
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
parent
b76730b77f
commit
fd876cb344
2 changed files with 6 additions and 0 deletions
|
|
@ -39,6 +39,7 @@ def _chat_assert_completion(client: AccessControlClient, key: str, model: str) -
|
|||
|
||||
|
||||
class TestProjectAllTeamModels:
|
||||
@pytest.mark.covers("other.auth.project.all_team_models_inherits_team_allowlist")
|
||||
@pytest.mark.parametrize("team_models", [[], [ALL_PROXY_MODELS]])
|
||||
def test_all_team_models_project_calls_team_allowed_model(
|
||||
self, client: AccessControlClient, resources: ResourceManager, team_models: list[str]
|
||||
|
|
@ -54,6 +55,7 @@ class TestProjectAllTeamModels:
|
|||
|
||||
_chat_assert_completion(client, key, TEAM_MODEL)
|
||||
|
||||
@pytest.mark.covers("other.auth.project.all_team_models_denied_outside_team")
|
||||
def test_all_team_models_project_denied_outside_team_list(
|
||||
self, client: AccessControlClient, resources: ResourceManager
|
||||
) -> None:
|
||||
|
|
@ -81,6 +83,7 @@ class TestProjectAllTeamModels:
|
|||
f"403 body must be a team model-access denial, got: {denied.body[:300]}"
|
||||
)
|
||||
|
||||
@pytest.mark.covers("other.auth.project.explicit_model_list_enforced")
|
||||
def test_project_explicit_model_list_calls_model(
|
||||
self, client: AccessControlClient, resources: ResourceManager
|
||||
) -> None:
|
||||
|
|
|
|||
|
|
@ -23,6 +23,9 @@
|
|||
- {id: other.auth.model_access_group.non_member_denied, module: other, tier: P0, area: auth, assertions: [non_member_denied], source: "auth_checks.py:3232", rationale: "That same grant reaches nothing outside the group, including provider models the group's wildcard does not cover"}
|
||||
- {id: other.auth.model_access_group.team_wildcard_bare_name_allowed, module: other, tier: P1, area: auth, assertions: [team_wildcard_bare_name_allowed], source: "auth_checks.py:3232 / LIT-5813", fail_before_fix: proven, rationale: "The same bare-name grant holds when the wildcard deployment is team-scoped and the team's allow-list is the group"}
|
||||
- {id: other.auth.model_access_group.team_non_member_denied, module: other, tier: P1, area: auth, assertions: [team_non_member_denied], source: "auth_checks.py:3232", rationale: "A team-level group grant reaches nothing outside the group"}
|
||||
- {id: other.auth.project.all_team_models_inherits_team_allowlist, module: other, tier: P1, area: auth, assertions: [all_team_models_inherits_team_allowlist], source: "auth_checks.py can_project_access_model / LIT-8967", fail_before_fix: proven, rationale: "A project whose models list is all-team-models can call any model its parent team can call, when the team allows all proxy models via [] or all-proxy-models"}
|
||||
- {id: other.auth.project.all_team_models_denied_outside_team, module: other, tier: P1, area: auth, assertions: [all_team_models_denied_outside_team], source: "auth_checks.py can_project_access_model / LIT-8967", fail_before_fix: proven, rationale: "An all-team-models project inherits a restricted team's list, so a team model still completes and a model outside it is denied 403 by the team check, not the project check"}
|
||||
- {id: other.auth.project.explicit_model_list_enforced, module: other, tier: P1, area: auth, assertions: [explicit_model_list_enforced], source: "auth_checks.py can_project_access_model", rationale: "A project with an explicit models list can call models on the list and is denied 403 project_model_access_denied for models off it"}
|
||||
- {id: other.auth.virtual_key.route_permission_enforced, module: other, tier: P0, area: auth, assertions: [route_permission_enforced], source: "route_checks.py:89-151", rationale: "allowed_routes whitelist denies disallowed routes"}
|
||||
- {id: other.auth.virtual_key.route_group_allowed, module: other, tier: P1, area: auth, assertions: [route_group_allowed], source: "route_checks.py:106-128", rationale: "allowed_routes=[llm_api_routes] grants all LLM endpoints"}
|
||||
- {id: other.auth.passthrough.model_allowlist_enforced, module: other, tier: P1, area: auth, assertions: [model_allowlist_enforced], source: "route_checks.py:135-151", rationale: "Passthrough enforces per-key model allow-lists"}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue