litellm/tests/integration/authorization
devin-ai-integration[bot] c13746c951
fix(router): price a model group from the deployments that serve it (#44732)
* fix(router): price a model group from the deployments that serve it

A model group's info read composed the group's own model_group_alias
entry into its deployments, a hop the router never takes: an alias is
resolved exactly once at request time, so a group reached as an alias
target is served by its own deployments. For the chain X -> T -> U the
price read for X included U's deployments too, and the free-model
budget waiver refused a free request to X on an over-budget key, while
GET /model_group/info reported U's providers and price for X.

The group info read now prices a group from the deployments routing
serves it with: the ones named after it, the routing group of that
name, or the wildcard route matching it when neither exists. The
budget waiver, GET /model_group/info, the rate limiters, and the
response headers all read the same set as routing. get_model_list
keeps its behavior for every other caller.

* test(router): give the paid fixtures explicit per-token prices

* test(router): call the routed-group read by name so the router coverage gate sees it

* test(integration): audit the alias chain budget waiver on every route, shape, and outage

Thirty-four cells under the management group prove an over-budget key is served through an alias chain entry at the price of the deployment that serves it, on chat, responses, and messages, sync and streamed, through the OpenAI and Anthropic SDKs and raw httpx on both replicas, with the chain middle, the reverse chain, a cost-map priced middle, a ghost middle, wildcard and routing-group targets, malformed and hostile inputs, a cached reply, a repointed alias, a provider failure, and two chaos bursts (a killed worker, a scripted outage)

---------

Co-authored-by: mateo-berri <277851410+mateo-berri@users.noreply.github.com>
2026-10-06 05:31:09 +00:00
..
_guardrail_opt_out.py fix(proxy): gate disable_global_guardrails on keys and teams to proxy admins (#42699) 2026-09-23 18:03:02 -07:00
_hidden_alias_budget.py fix(auth): resolve hidden model_group_alias entries in the zero-cost budget check (#43741) 2026-10-03 16:35:11 -07:00
test_access_group_model_listing.py test(integration): regression tests for July cost tracking, budgeting and spend bugs (#42694) 2026-09-23 09:51:56 -07:00
test_alias_chain_budget_waiver.py fix(router): price a model group from the deployments that serve it (#44732) 2026-10-06 05:31:09 +00:00
test_audit_any_sweep_auth.py refactor(types): replace Any with proven types in 9 files (#44389) 2026-10-03 21:03:16 +00:00
test_bedrock_passthrough_model_access.py test(integration): regression tests for July cost tracking, budgeting and spend bugs (#42694) 2026-09-23 09:51:56 -07:00
test_cli_sso_login_ui_disabled.py fix(sso): let CLI and Claude Code gateway sign-in through on DISABLE_ADMIN_UI nodes (#44620) 2026-10-05 21:59:50 +00:00
test_customer_model_allowlist.py feat(proxy): limit which models an end user can call (#43904) 2026-10-05 21:58:03 +00:00
test_deprecated_key_lookup_cache.py test(proxy): migrate DB and Redis backed proxy tests into tests/integration (#43996) 2026-10-01 09:23:36 -07:00
test_hidden_alias_budget_bypass.py fix(proxy): judge the free-model budget waiver by the group an alias routes to (#44638) 2026-10-06 02:44:35 +00:00
test_hidden_alias_budget_bypass_chaos.py fix(auth): resolve hidden model_group_alias entries in the zero-cost budget check (#43741) 2026-10-03 16:35:11 -07:00
test_jwt_auto_register_map_existing_key.py feat(jwt): auto_register_map_existing_key maps JWT to the user's existing virtual key (#42375) 2026-10-02 12:11:33 -07:00
test_jwt_default_team_provisioning.py test(integration): regression tests for July cost tracking, budgeting and spend bugs (#42694) 2026-09-23 09:51:56 -07:00
test_jwt_mapped_key_email_backfill.py test(integration): regression tests for July cost tracking, budgeting and spend bugs (#42694) 2026-09-23 09:51:56 -07:00
test_key_alias_model_access.py fix(proxy): authorize key model aliases the same way as team aliases (#43049) 2026-09-24 19:51:02 -07:00
test_key_bound_to_unknown_user.py test(integration): move legacy proxy, router and Redis tests into tests/integration (#44128) 2026-10-01 23:00:54 -07:00
test_key_guardrail_opt_out.py fix(proxy): gate disable_global_guardrails on keys and teams to proxy admins (#42699) 2026-09-23 18:03:02 -07:00
test_key_guardrail_opt_out_chaos.py fix(proxy): gate disable_global_guardrails on keys and teams to proxy admins (#42699) 2026-09-23 18:03:02 -07:00
test_key_guardrail_opt_out_runtime.py fix(proxy): gate disable_global_guardrails on keys and teams to proxy admins (#42699) 2026-09-23 18:03:02 -07:00
test_object_permission_lookup.py test(integration): regression tests for July cost tracking, budgeting and spend bugs (#42694) 2026-09-23 09:51:56 -07:00
test_rag_query_vector_store_allowlist.py fix(proxy): enforce key/team vector_stores allowlist on /v1/rag/query (#43953) 2026-10-01 13:48:41 -07:00
test_team_admin_gate.py test(ci): repair MCP Responses and budget fixtures (#43788) 2026-09-29 23:29:52 -07:00
test_team_member_permissions.py test(integration): move legacy proxy, router and Redis tests into tests/integration (#44128) 2026-10-01 23:00:54 -07:00
test_team_scoped_models.py fix(caching): key response cache by router model group in litellm_metadata (#44542) 2026-10-05 17:06:21 +00:00
test_warmed_policy.py test(integration): pin the team-admin status-code matrix across every management route (#43249) 2026-09-26 11:32:24 -07:00
test_wildcard_model_access.py test(integration): move legacy proxy, router and Redis tests into tests/integration (#44128) 2026-10-01 23:00:54 -07:00