litellm/tests/test_litellm/proxy/management_endpoints
joshua-berri 79756cbb9b
feat(agents): enforce authoritative agent permissions (#43721)
* feat(agents): authoritative permissions

* fix: enforce authoritative managed agent permissions

* fix(agents): only consult the identity store for managed targets

is_agent_allowed entered the identity-store path whenever a prisma client
was configured, so an ordinary agent paired with an internal user returned
503 instead of 200. Classify the target from the registry first and fall
back to the store only when the registry has no entry, so an unmanaged
target never depends on the store being reachable.

* fix(agents): gate the managed path on an admitted policy object

Ten call sites branched on `managed_agent_policy is not None`, which any
MagicMock attribute satisfies, so the managed path fired on unmanaged
subjects and died in Pydantic validation as a 503. Route every check
through a shared helper that requires a real AgentResponse.

* test(mcp): stub the writer replica the fresh-policy reads use

reload_admitted_user now passes check_db_only through to get_user_object,
so the user row is read from writer_db. Point the mocks at the replica the
code actually reads and give each parametrized case its own user id.

* fix(agents): cap a managed agent at the invoking team's agents

resolve_agent_access returned the managed policy's grants before the
agent_caller ceiling was applied, so a managed agent acting on behalf of a
user reached agents that user's team was never granted. Intersect with the
caller ceiling the unmanaged path already honours.

* fix(agents): restore token narrowing and scope the private-access suppressions

The managed-model check lost its valid_token narrowing when it moved to the
shared helper. Make the caller-access resolver public rather than reaching
into it from module scope, and give each remaining private access a reason.

* docs(agents): drop the comment claiming admins skip the A2A permission check

The check has never had an admin bypass on this path, so the comment
described behaviour the code does not implement.

* test(proxy): stub the writer reads and restore the MCP manager singleton

Fresh-policy user lookups read writer_db, so the team and rest-endpoint
mocks stubbed a replica the code no longer reads, and the dashboard
session fake still had the pre-kwarg signature. The manager reload also
rebound global_mcp_server_manager in every MCP module without restoring
it, leaking an empty manager into later files.

* style: sort imports under the litellm package ruff config

* fix(mcp): cap a managed agent's servers and tools at the invoking caller

managed_agent_servers and managed_agent_tools returned the agent's own
grants without the agent_caller ceiling the unmanaged resolvers apply, so
a managed agent reached MCP servers and tools the echoed caller could not.
Call the existing ceiling helpers on both axes.

* refactor(mcp): return the caller-capped tools without an interim list

The ceiling helper already returns a sequence, so materializing it into a
list added a mutable collection for nothing. Sort at the return sites
instead, which also makes the tool order stable across both branches.

* fix(agents): preserve actor ceilings during managed target checks

* fix(agents): keep managed permission ceilings authoritative

* fix(mcp): fail closed on authoritative caller team outages

---------

Co-authored-by: Joshua Valluru <326636767+joshua-berri@users.noreply.github.com>
2026-09-30 11:11:37 -07:00
..
management_v1 fix(team): keep a forked member budget's reset window and audit bulk member budget writes 2026-09-17 15:17:00 -07:00
policy_endpoints fix(registry): correct eu Claude 3.5 Haiku Bedrock pricing, add Nova v1 tool_choice, Azure gpt-5.5 snapshot retirement 2026-09-09 13:16:04 +00:00
scim fix(proxy): evict the cached user row when SCIM or /user/delete removes a user 2026-09-21 13:51:26 -07:00
search_endpoints fix(proxy): sync search tools into the router on management writes 2026-08-26 11:46:54 -07:00
usage_endpoints fix(proxy): emit SSE keepalives on queue, rag, azure passthrough, usage chat and policy enrich streams (#39273) 2026-09-03 18:23:37 -07:00
jwt_key_mapping_doubles.py test(proxy): share the jwt key mapping test doubles across the deletion endpoint tests 2026-09-18 00:17:45 +00:00
test_access_group_endpoints.py feat(agents): attach access groups to agents and enforce them for models, MCP servers and agent calls 2026-09-17 19:24:14 +00:00
test_access_group_management.py test(budgets): cover management null handling 2026-09-16 21:42:55 -07:00
test_activity_tenant_scoping.py fix(proxy): deny agent access when key and team grants resolve to nothing (#36221) 2026-08-07 20:44:11 +00:00
test_auto_router_endpoints.py fix(autorouter): compare historical and new savings consistently (#43348) 2026-09-29 12:40:19 -07:00
test_budget_endpoints.py feat(proxy): add tpd_limit (tokens per day) for batch submissions 2026-09-13 10:06:07 +00:00
test_cache_settings_endpoints.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_callback_management_endpoints.py feat(langfuse): migrate the sdk callback to langfuse v4 (#36741) 2026-09-24 23:22:56 -07:00
test_common_daily_activity.py fix(proxy): recover session key owners from daily spend for usage attribution (#43642) 2026-09-29 15:36:09 -07:00
test_common_utils.py fix(proxy): gate disable_global_guardrails on keys and teams to proxy admins (#42699) 2026-09-23 18:03:02 -07:00
test_compliance_endpoints.py Revert "refactor(guardrails): rename scoped-out evaluation status from not_run to skipped" 2026-09-14 23:46:09 +00:00
test_config_override_endpoints.py feat(vault): add separate login and secret namespaces for HashiCorp Vault 2026-09-17 01:41:48 +00:00
test_coordination_redis_endpoints.py test: drop two inert type: ignore comments 2026-09-19 14:22:19 -07:00
test_cost_estimate_endpoint.py test: run the 30 test files stranded in the second mirror (#37595) 2026-08-20 10:59:43 -07:00
test_cost_tracking_settings.py Merge pull request #41832 from BerriAI/litellm_lit_8111_cache_read_missing_rate 2026-09-18 10:56:25 -07:00
test_credential_migration.py fix(mcp): encrypt stored static headers and stdio environment (#40164) 2026-09-07 16:03:06 -07:00
test_customer_budget.py
test_customer_endpoints.py test(proxy): include temp budget fields in customer budget table fixture 2026-09-17 18:10:00 +00:00
test_delete_callbacks_endpoint.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_delete_verification_tokens_failed.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_encryption_endpoints.py
test_entraid_app_roles.py fix(ui_sso): resolve highest privilege Entra app role, not first in claim (#36728) 2026-08-27 10:26:45 -07:00
test_gateway_request_endpoints.py feat(sgr): make the gateway middleware the source of truth for successful requests (#35717) 2026-08-05 12:40:47 -07:00
test_id_jag_assertion_capture.py feat(mcp): warn when an oauth2_id_jag server outruns the SSO provider's assertion capture (#35394) 2026-09-05 12:43:09 -07:00
test_internal_user_endpoints.py revert: "feat(usage): search team keys beyond the top-N in the Team usage view (#42857)" (#43377) 2026-09-28 21:47:46 +00:00
test_key_management_endpoints.py fix(ui): keep MCP permissions visible after key, team and MCP server saves (#43810) 2026-09-29 22:49:20 -07:00
test_mcp_connector_import.py fix(mcp): harden connector import auth handling and registration 2026-08-29 13:41:22 -07:00
test_mcp_management_endpoints.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_model_insights_endpoints.py refactor: clean up fresh tech debt from 2026-09-28 (#43674) 2026-09-29 02:15:12 -07:00
test_model_management_endpoints.py fix(proxy): validate model credential name only when it changes (#42701) 2026-09-23 07:34:32 -07:00
test_org_admin_team_access.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_organization_endpoints.py Merge pull request #41620 from BerriAI/litellm_team_member_temp_budget_increase 2026-09-18 11:38:34 -07:00
test_password_endpoints.py test: deflake fuzzy picker, breached-password HIBP, and MCP stdio timeout tests (rolling deflake 2026-09-22) (#42125) 2026-09-23 08:44:59 -07:00
test_policy_endpoints.py
test_project_org_authz.py feat(proxy): let team admins manage projects via team_admin_editable_team_fields 2026-09-19 01:02:50 +00:00
test_prompt_cache_prediction.py Revert "test: keep prompt cache prediction logic tests and drop only their price pins" 2026-09-18 00:40:38 +00:00
test_prompt_caching_requests.py feat(ui): show prompt caching requests and net savings 2026-09-19 18:27:38 -07:00
test_ptu_model_settings.py feat(router): limit heuristic_v2 auto-routers to one without the auto_router license feature (#39468) 2026-09-03 13:39:58 -07:00
test_router_settings_endpoints.py feat(router): add group-scoped priority routing strategy (#42378) 2026-09-22 13:09:38 -07:00
test_saml_sso.py fix(sso): resolve multi-valued role claims to the highest privilege role (#39480) 2026-09-02 22:44:17 -07:00
test_session_endpoints.py fix(proxy): revoke UI session tokens on logout and password change (#42463) 2026-09-23 10:31:38 +02:00
test_tag_management_endpoints.py test(budgets): avoid mutable fixture state 2026-09-16 22:06:31 -07:00
test_team_admin_field_permissions.py feat(proxy): let team admins update member key budgets when enabled (#42555) 2026-09-25 01:54:52 +00:00
test_team_callback_endpoints.py feat(arize): per-team success and error sampling rates for the Arize AX callback (#42383) 2026-09-22 11:21:40 -05:00
test_team_default_params.py refactor(proxy): make the config file win over the database 2026-09-18 01:28:21 -07:00
test_team_endpoints.py feat(agents): enforce authoritative agent permissions (#43721) 2026-09-30 11:11:37 -07:00
test_team_model_alias_merge.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_tool_management_endpoints.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_ui_sso.py fix(sso): gate /sso/debug routes behind ENABLE_SSO_DEBUG, off by default (#43150) 2026-09-25 20:58:17 +02:00
test_workflow_management_endpoints.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00