litellm/tests/test_litellm/router_utils
abhi 84e2d4e23c fix: address review findings (team-scoping leak, sentinel collision, log dedup)
Three issues flagged by automated PR review (greptile-apps, veria-ai), all confirmed real and reproduced before fixing:

1. [High/Security] Team-owned deployments entered the global canonical index
   unconditionally. A no-team (unrestricted) key could request an unclaimed
   spelling of a model (e.g. the dated Anthropic ID) whose only server was a
   team's private deployment, resolve onto it, and use that team's
   credentials/quota -- target-authorization passes for unrestricted keys and
   doesn't itself re-derive team ownership. Fixed by excluding any deployment
   with model_info.team_id set from the index entirely: a team boundary is an
   access/billing boundary exactly like the cross-provider boundary this
   module already respects, and team-scoped models remain reachable exactly as
   before, via team_public_model_name through the existing team-route
   machinery this module never touches.

2. [P1] Sentinel collision defeated the ambiguity guard: index.get(key,
   '__absent__') treated a model group literally named '__absent__' as a
   missing entry, so a second group with the same identity would silently
   overwrite it instead of triggering the ambiguity decline. Fixed with a
   proper 'in' check.

3. [P2] Log deduplication was keyed on target alone, so a second distinct
   requested spelling resolving to an already-logged target never got its own
   log line -- undercounting the (requested, target) cardinality that's the
   whole point of the observability story (sizing follow-up-resolution
   demand). Now keyed on the (requested, target) pair.

Added 5 regression tests reproducing each bug pre-fix and asserting the fixed
behavior. Full affected suite: 522 passed. router_code_coverage: 0.0% untested.
ruff-strict BLE001/PERF401: unchanged at base parity. basedpyright: new module
0 errors.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-15 11:18:57 -07:00
..
pre_call_checks feat(router): independent, default-on deployment affinity for the auto-router (#36146) 2026-08-08 13:02:29 -07:00
test_add_retry_fallback_headers.py feat(router): add separate ITPM/OTPM deployment rate limits (#31952) 2026-07-05 21:58:35 +05:30
test_auto_router_model_naming.py feat(complexity_router): let operators rename the four complexity tiers (#35893) 2026-08-05 09:42:57 -07:00
test_cooldown_cache.py fix(router): cool down failed fallback deployments and correct cooldown TTL after Redis backfill (#35104) 2026-08-10 16:51:55 -07:00
test_cooldown_handlers.py feat(router): make routing groups callable as virtual models and list them in /v1/models (#36519) 2026-08-11 18:41:19 -07:00
test_fallback_event_handlers.py fix(router): cool down failed fallback deployments and correct cooldown TTL after Redis backfill (#35104) 2026-08-10 16:51:55 -07:00
test_health_check_allowed_fails_integration.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_health_state_cache.py feat(router): add health-check-driven routing behind opt-in flag 2026-03-27 20:57:08 +05:30
test_router_canonical_model_resolution.py fix: address review findings (team-scoping leak, sentinel collision, log dedup) 2026-08-15 11:18:57 -07:00
test_router_health_check_routing.py Litellm ishaan april4 2 (#25150) 2026-04-04 23:09:42 +00:00
test_router_interactions_endpoints.py Gemini managed agents support (#28270) 2026-05-19 16:02:03 -07:00
test_router_utils_common_utils.py fix(router): warn when a deployment's credentials contradict its provider (#36486) 2026-08-10 18:41:19 -07:00