litellm/tests/test_litellm/proxy/_experimental
Tin Chi Lo 230ca7d195 feat(mcp): graft aws_sigv4 to the v2 resolver via the aws_auth seam
aws_sigv4 signs every request, so it cannot ride the header-extraction seam the other grafted
modes use; it grafts at MCPClient.aws_auth instead. _create_mcp_client now asks the bridge's
resolve_v2_aws_auth(server) for the signer when the flag is on and falls back to v1's
MCPSigV4Auth otherwise. The bridge wires HttpxSigV4Signer into the provider and maps a v1
aws_sigv4 server's aws_* fields onto AwsSigV4Config (assume-role / static keys / ambient),
deferring to v1 for the one shape v2 can't yet represent (assume-role with explicit base keys).

Tests cover the credential-source mapping, the signer signing a real request, the role+base-keys
defer-to-v1 case, the flag-off and non-aws defer paths. 83 tests pass; the bridge typechecks
clean and the manager imports the guarded hook.
2026-06-18 17:02:21 -07:00
..
mcp_server feat(mcp): graft aws_sigv4 to the v2 resolver via the aws_auth seam 2026-06-18 17:02:21 -07:00