litellm/tests
yassin e02f19fdd9 fix(auth): exempt the reserved UI session team from the absent-team refusal
Every Admin UI session key is stamped with team_id=litellm-dashboard, a reserved
sentinel that /team/new refuses to create, so resolving it against the database can
only fail. The absent-versus-unreadable distinction #36837 added read that as a
deleted team and 404'd every dashboard request. Resolve the sentinel from the token
instead of asking for a row that will never exist.

The reserved id alone does not earn the exemption. The synthesized team's empty
models reads as every model, so an identity that merely names the sentinel is
widened rather than waved through, and several auth paths take team_id straight
from data the proxy did not mint: JWT claims, an OAuth2 introspection response, a
custom auth handler's return value. Rather than enumerate the producers to exclude,
require proof of where the credential came from. A database-minted session key is
already marked as a virtual key. The EXPERIMENTAL_UI_LOGIN blob has no key row, and
a proxy-admin one returns before the virtual-key paths, so mark it where it is
decrypted with the proxy's own ui_hash_key. Both markers are stripped from validated
input, so no claim, header or handler return can carry one in.

That leaves the id itself, which /team/new reserves but key creation did not, so a
proxy admin could put an ordinary key on the sentinel team and it would inherit the
exemption along with the skip of its owner's user-level model check. Reserve the id
on the key create and update paths too. The UI mints its session key through
generate_key_helper_fn directly, so it never passes through either one.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-08-14 16:43:17 -07:00
..
agent_tests test: repair stale CircleCI contracts 2026-08-08 12:19:29 -07:00
audio_tests test: remove tests that never execute 2026-08-12 10:45:38 -07:00
base_sdk_tests fix(deps): ship boto3 with the base SDK so bedrock works out of the box (#36568) 2026-08-11 14:39:10 -07:00
basic_proxy_startup_tests
batches_tests test: remove tests that never execute 2026-08-12 10:45:38 -07:00
benchmarks test(benchmarks): run shared logging executor inline to make CodSpeed measurements deterministic (#32435) 2026-07-09 11:14:22 +03:00
code_coverage_tests fix(ci): report budgets the startup guard cannot resolve 2026-08-10 18:12:18 +00:00
documentation_tests fix(ci): make the env-key doc gate see bare get_secret and get_secret_str reads (#35996) 2026-08-05 14:49:55 -07:00
e2e Merge branch 'litellm_internal_staging' into litellm_shadcn_modelhub_0814 2026-08-14 09:59:57 -07:00
enterprise fix(proxy): report has_more false on caller-scoped file list pages 2026-08-08 17:28:43 -07:00
guardrails_tests fix(guardrails): honor configured timeout in Zscaler AI Guard (#36110) 2026-08-07 00:25:52 +00:00
image_gen_tests test: remove tests that never execute 2026-08-12 10:45:38 -07:00
integration
litellm fix(proxy): deny agent access when key and team grants resolve to nothing (#36221) 2026-08-07 20:44:11 +00:00
litellm-proxy-extras test: remove tests that never execute 2026-08-12 10:45:38 -07:00
litellm_core_utils
litellm_utils_tests fix(reset_budget_job): atomic budget cascade with chunked reset scans (#36287) 2026-08-10 14:42:36 -07:00
llm_responses_api_testing test: repair stale CircleCI contracts 2026-08-08 12:19:29 -07:00
llm_translation Merge pull request #36685 from BerriAI/litellm_restore_shadowed_tests 2026-08-12 12:06:37 -07:00
load_tests
local_testing test: remove tests that never execute 2026-08-12 10:45:38 -07:00
logging_callback_tests test: address review on the restored SQS tests 2026-08-12 11:47:11 -07:00
mcp_tests fix(mcp): keep REST tool listing in step with key/team grant enforcement 2026-07-30 22:13:10 -07:00
multi_instance_e2e_tests
ocr_tests test(ocr): use mistral-document-ai-2512 in azure_ai OCR tests 2026-07-15 18:13:22 -07:00
old_proxy_tests/tests
openai_endpoints_tests fix(batches): register managed output files on batch cancel 2026-08-05 18:28:52 -07:00
otel_tests fix(cli): mint per-session agent credential on lite login (#31072) 2026-06-26 09:05:15 -07:00
pass_through_tests test(pass-through): de-flake vertex spend-log test by routing through the proxy (#31689) 2026-06-30 15:27:48 -07:00
pass_through_unit_tests fix(proxy): re-assert the authenticated identity on passthrough requests (#36121) 2026-08-07 00:41:29 +00:00
proxy_admin_ui_tests fix(access groups): sync assigned_team_ids from the team write paths (#36825) 2026-08-14 04:45:36 +00:00
proxy_behavior test: repair stale CircleCI contracts 2026-08-08 12:19:29 -07:00
proxy_e2e_anthropic_messages_tests
proxy_migration_tests test(docker): gate the componentized gateway and backend images on an arbitrary-uid offline boot (#36136) 2026-08-07 09:57:37 -07:00
proxy_security_tests
proxy_unit_tests Merge pull request #36714 from BerriAI/litellm_check_batch_cost_poll_starvation 2026-08-13 18:41:45 -07:00
router_unit_tests test: remove tests that never execute 2026-08-12 10:45:38 -07:00
scim_tests
search_tests feat(tinyfish): make search provider permissive, attribute errors (#31997) 2026-07-03 10:17:11 -07:00
spend_tracking_tests
store_model_in_db_tests feat(team): custom metadata validation hook for team create and update (#33353) 2026-08-03 18:37:45 -07:00
test_litellm fix(auth): exempt the reserved UI session team from the absent-team refusal 2026-08-14 16:43:17 -07:00
unified_google_tests
vector_store_tests
windows_tests
__init__.py
_fake_openai_endpoint_server.py
_flush_vcr_cache.py
_live_test_helpers.py
_openai_record_replay_proxy.py
_vcr_conftest_common.py
_vcr_redis_persister.py
_ws_vcr.py test(realtime): record and replay websocket traffic in redis vcr cassettes (#32390) 2026-07-08 00:19:06 -07:00
eval_swe_bench.py
fake_openai_endpoint.py
gettysburg.wav
large_text.py
openai_batch_completions.jsonl
pyrightconfig.json
README.MD [Feat] MCP Gateway Fine-grained Tools Addition (#15153) 2025-10-03 10:16:29 -07:00
test_anthropic_compaction_usage.py
test_budget_management.py
test_callbacks_on_proxy.py
test_debug_warning.py
test_default_encoding_non_root.py
test_end_users.py
test_fallbacks.py
test_gpt5_azure_temperature_support.py
test_health.py
test_keys.py
test_litellm_proxy_responses_config.py
test_logging.conf
test_models.py
test_new_vector_store_endpoints.py
test_openai_endpoints.py
test_organizations.py
test_otel_thread_leak.py
test_presidio_latency.py
test_proxy_server_non_root.py
test_ratelimit.py
test_resource_cleanup.py
test_service_logger_otel.py fix(langfuse): send v4 ingestion header for otel callback (#33907) 2026-07-18 20:36:51 -07:00
test_spend_logs.py
test_team.py
test_team_logging.py
test_team_members.py
test_users.py

In total litellm runs 1000+ tests

[02/20/2025] Update:

To make it easier to contribute and map what behavior is tested,

we've started mapping the litellm directory in tests/test_litellm

This folder can only run mock tests.