litellm/tests/test_litellm/proxy/_experimental/mcp_server
joshua-berri 79756cbb9b
feat(agents): enforce authoritative agent permissions (#43721)
* feat(agents): authoritative permissions

* fix: enforce authoritative managed agent permissions

* fix(agents): only consult the identity store for managed targets

is_agent_allowed entered the identity-store path whenever a prisma client
was configured, so an ordinary agent paired with an internal user returned
503 instead of 200. Classify the target from the registry first and fall
back to the store only when the registry has no entry, so an unmanaged
target never depends on the store being reachable.

* fix(agents): gate the managed path on an admitted policy object

Ten call sites branched on `managed_agent_policy is not None`, which any
MagicMock attribute satisfies, so the managed path fired on unmanaged
subjects and died in Pydantic validation as a 503. Route every check
through a shared helper that requires a real AgentResponse.

* test(mcp): stub the writer replica the fresh-policy reads use

reload_admitted_user now passes check_db_only through to get_user_object,
so the user row is read from writer_db. Point the mocks at the replica the
code actually reads and give each parametrized case its own user id.

* fix(agents): cap a managed agent at the invoking team's agents

resolve_agent_access returned the managed policy's grants before the
agent_caller ceiling was applied, so a managed agent acting on behalf of a
user reached agents that user's team was never granted. Intersect with the
caller ceiling the unmanaged path already honours.

* fix(agents): restore token narrowing and scope the private-access suppressions

The managed-model check lost its valid_token narrowing when it moved to the
shared helper. Make the caller-access resolver public rather than reaching
into it from module scope, and give each remaining private access a reason.

* docs(agents): drop the comment claiming admins skip the A2A permission check

The check has never had an admin bypass on this path, so the comment
described behaviour the code does not implement.

* test(proxy): stub the writer reads and restore the MCP manager singleton

Fresh-policy user lookups read writer_db, so the team and rest-endpoint
mocks stubbed a replica the code no longer reads, and the dashboard
session fake still had the pre-kwarg signature. The manager reload also
rebound global_mcp_server_manager in every MCP module without restoring
it, leaking an empty manager into later files.

* style: sort imports under the litellm package ruff config

* fix(mcp): cap a managed agent's servers and tools at the invoking caller

managed_agent_servers and managed_agent_tools returned the agent's own
grants without the agent_caller ceiling the unmanaged resolvers apply, so
a managed agent reached MCP servers and tools the echoed caller could not.
Call the existing ceiling helpers on both axes.

* refactor(mcp): return the caller-capped tools without an interim list

The ceiling helper already returns a sequence, so materializing it into a
list added a mutable collection for nothing. Sort at the return sites
instead, which also makes the tool order stable across both branches.

* fix(agents): preserve actor ceilings during managed target checks

* fix(agents): keep managed permission ceilings authoritative

* fix(mcp): fail closed on authoritative caller team outages

---------

Co-authored-by: Joshua Valluru <326636767+joshua-berri@users.noreply.github.com>
2026-09-30 11:11:37 -07:00
..
auth feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
faults test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
guardrail_translation feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
outbound_credentials test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
conftest.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_byok_credential_cache.py fix(caching): propagate auth cache invalidation over Redis Cluster via a node-level pub/sub client (#43110) 2026-09-25 07:56:46 -07:00
test_byok_oauth_endpoints.py fix(proxy): revoke UI session tokens on logout and password change (#42463) 2026-09-23 10:31:38 +02:00
test_callback_oauth_error_responses.py Litellm oss staging 250526 (#28770) 2026-05-26 11:57:39 -07:00
test_capabilities.py feat(mcp): configure protocol versions and capability discovery (#43169) 2026-09-25 13:13:52 -07:00
test_client_allowlist.py feat(mcp): give each allowed MCP client an alias and a value 2026-09-18 22:29:17 +00:00
test_contracts.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_db_credentials.py feat(mcp): let proxy admins force-close live MCP sessions and revoke stored user credentials 2026-09-18 01:01:26 +00:00
test_discoverable_endpoints.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_gateway_dcr_flow.py fix(proxy): answer 503 temporarily_unavailable when the token exchange cannot verify the subject token 2026-09-17 16:39:02 -07:00
test_idp_token_exchange.py fix(proxy): word the token exchange's 503 by whether the database fault can clear 2026-09-17 17:20:17 -07:00
test_is_tool_name_prefixed.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_jwt_mcp_enforcement.py fix(mcp): resolve team.access_group_ids → MCP servers (#28997) 2026-05-27 12:36:50 -07:00
test_jwt_mcp_simple.py fix(mcp): resolve team.access_group_ids → MCP servers (#28997) 2026-05-27 12:36:50 -07:00
test_mcp_block_recording.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_cost_calculator.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_custom_fields.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_debug.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_discovery.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_elicitation_handler.py test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
test_mcp_env_vars.py fix(mcp): report reachability without stored credentials (#43240) 2026-09-26 16:44:49 -07:00
test_mcp_guardrail_usage_monitor.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_header_alias_utils.py feat(mcp): use x-mcp-<access_group>-* headers as default upstream credentials for group members (#39717) 2026-09-04 12:45:24 -07:00
test_mcp_hook_extra_headers.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_mcp_max_concurrent_requests.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_mcp_metadata_preservation.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_oauth_passthrough.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_oauth_passthrough_cold_start.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_oauth_passthrough_tools.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_partial_update.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_proxy_mode.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_sampling_completion_flow.py test(mcp): update MCP suites for SDK2 handler signatures and ctx var 2026-09-18 23:34:30 +00:00
test_mcp_sampling_model_access.py test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
test_mcp_sampling_model_resolution.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_priority_selection.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_request_builder.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_response_conversion.py test(mcp): update MCP suites for SDK2 handler signatures and ctx var 2026-09-18 23:34:30 +00:00
test_mcp_sampling_tool_conversion.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_server.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_server_identity_env.py test: trim mcp fixture docstring and reload comment 2026-09-01 11:06:08 +00:00
test_mcp_server_manager.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_mcp_session_logging.py Add MCP semantic conventions to otelv2 (#29468) 2026-06-02 11:45:36 -07:00
test_mcp_sigv4_auth.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_stale_session.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_tool_search.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_toolset_scope.py test(mcp): preserve toolset scope across explicit context 2026-09-21 12:31:48 -07:00
test_oauth2_flow_backfill.py feat(mcp): startup backfill stamping oauth2_flow on legacy null rows (#32290) 2026-07-06 18:42:08 -07:00
test_oauth2_token_cache.py test(mcp): give the new cache and tombstone patches TQ008 reasons and match the keyword eviction call 2026-09-18 02:49:41 +00:00
test_oauth_identity_binding.py fix(mcp): preserve identity checks across cached OAuth credentials 2026-09-10 13:08:46 -07:00
test_oauth_issuer_stamp_backfill.py fix(mcp): never write discovery results to the row, heal rows a release already stamped, and retry failed discovery with backoff 2026-07-29 17:51:22 -07:00
test_openapi_to_mcp_generator.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_openapi_tool_auth.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_operations.py feat(mcp): configure protocol versions and capability discovery (#43169) 2026-09-25 13:13:52 -07:00
test_proxy_api_credentials.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_rest_endpoints.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_result_conversion.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_semantic_tool_filter.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_server_resolution.py refactor(mcp): add shared server resolver without changing callers (#43262) 2026-09-26 13:01:37 -07:00
test_short_mcp_tool_prefix.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_ui_session_utils.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_utils.py fix(mcp): preserve discovery attribution and sanitize logging headers (#42541) 2026-09-22 14:26:48 -07:00