diff --git a/tests/e2e/access_control/test_project_all_team_models_e2e.py b/tests/e2e/access_control/test_project_all_team_models_e2e.py index 36820916d40..b58f97e6562 100644 --- a/tests/e2e/access_control/test_project_all_team_models_e2e.py +++ b/tests/e2e/access_control/test_project_all_team_models_e2e.py @@ -39,6 +39,7 @@ def _chat_assert_completion(client: AccessControlClient, key: str, model: str) - class TestProjectAllTeamModels: + @pytest.mark.covers("other.auth.project.all_team_models_inherits_team_allowlist") @pytest.mark.parametrize("team_models", [[], [ALL_PROXY_MODELS]]) def test_all_team_models_project_calls_team_allowed_model( self, client: AccessControlClient, resources: ResourceManager, team_models: list[str] @@ -54,6 +55,7 @@ class TestProjectAllTeamModels: _chat_assert_completion(client, key, TEAM_MODEL) + @pytest.mark.covers("other.auth.project.all_team_models_denied_outside_team") def test_all_team_models_project_denied_outside_team_list( self, client: AccessControlClient, resources: ResourceManager ) -> None: @@ -81,6 +83,7 @@ class TestProjectAllTeamModels: f"403 body must be a team model-access denial, got: {denied.body[:300]}" ) + @pytest.mark.covers("other.auth.project.explicit_model_list_enforced") def test_project_explicit_model_list_calls_model( self, client: AccessControlClient, resources: ResourceManager ) -> None: diff --git a/tests/e2e/coverage_registry/other.yaml b/tests/e2e/coverage_registry/other.yaml index 3bd98ff5b0b..f21624e3501 100644 --- a/tests/e2e/coverage_registry/other.yaml +++ b/tests/e2e/coverage_registry/other.yaml @@ -23,6 +23,9 @@ - {id: other.auth.model_access_group.non_member_denied, module: other, tier: P0, area: auth, assertions: [non_member_denied], source: "auth_checks.py:3232", rationale: "That same grant reaches nothing outside the group, including provider models the group's wildcard does not cover"} - {id: other.auth.model_access_group.team_wildcard_bare_name_allowed, module: other, tier: P1, area: auth, assertions: [team_wildcard_bare_name_allowed], source: "auth_checks.py:3232 / LIT-5813", fail_before_fix: proven, rationale: "The same bare-name grant holds when the wildcard deployment is team-scoped and the team's allow-list is the group"} - {id: other.auth.model_access_group.team_non_member_denied, module: other, tier: P1, area: auth, assertions: [team_non_member_denied], source: "auth_checks.py:3232", rationale: "A team-level group grant reaches nothing outside the group"} +- {id: other.auth.project.all_team_models_inherits_team_allowlist, module: other, tier: P1, area: auth, assertions: [all_team_models_inherits_team_allowlist], source: "auth_checks.py can_project_access_model / LIT-8967", fail_before_fix: proven, rationale: "A project whose models list is all-team-models can call any model its parent team can call, when the team allows all proxy models via [] or all-proxy-models"} +- {id: other.auth.project.all_team_models_denied_outside_team, module: other, tier: P1, area: auth, assertions: [all_team_models_denied_outside_team], source: "auth_checks.py can_project_access_model / LIT-8967", fail_before_fix: proven, rationale: "An all-team-models project inherits a restricted team's list, so a team model still completes and a model outside it is denied 403 by the team check, not the project check"} +- {id: other.auth.project.explicit_model_list_enforced, module: other, tier: P1, area: auth, assertions: [explicit_model_list_enforced], source: "auth_checks.py can_project_access_model", rationale: "A project with an explicit models list can call models on the list and is denied 403 project_model_access_denied for models off it"} - {id: other.auth.virtual_key.route_permission_enforced, module: other, tier: P0, area: auth, assertions: [route_permission_enforced], source: "route_checks.py:89-151", rationale: "allowed_routes whitelist denies disallowed routes"} - {id: other.auth.virtual_key.route_group_allowed, module: other, tier: P1, area: auth, assertions: [route_group_allowed], source: "route_checks.py:106-128", rationale: "allowed_routes=[llm_api_routes] grants all LLM endpoints"} - {id: other.auth.passthrough.model_allowlist_enforced, module: other, tier: P1, area: auth, assertions: [model_allowlist_enforced], source: "route_checks.py:135-151", rationale: "Passthrough enforces per-key model allow-lists"}