mirror of
https://github.com/BerriAI/litellm.git
synced 2026-08-28 05:25:59 +00:00
The SSO and Email Server settings pages read only stored config, so a gateway configured entirely through environment variables rendered every field blank even though both features were live. Rather than add per-endpoint env fallback, resolve each setting through one typed config object. A FieldDescriptor names, for one setting, where it lives in the stored row (db_key), which process env var carries it (env_var), whether it is a secret, and its effective default. A pure resolve_fields reconciles a descriptor table against the stored row and the process environment with a fixed precedence and reports per-field provenance (db, env, default, or unset). The SSO descriptor table single-sources the field-to-env mapping that the read and write paths previously duplicated, so they can no longer drift. get_sso_settings and the /get/config/callbacks alerting block read through the resolver instead of their own inline fallbacks. get_sso_settings no longer decrypts stored values into os.environ; decryption happens once inside the resolver via the pure helper, so a GET stops mutating the process environment. The SSO response carries provenance so the UI can distinguish an env-sourced value from a stored one, and secrets are masked at the endpoint (the resolver returns them unmasked so the login path could consume them). os.environ remains the runtime carrier; the SSO login and mail-send paths are unchanged. The settings pages also submit only fields an admin actually edited, so a rendered mask or env-sourced value is never written back over a working secret, and generic_scope is a real SSO form field. Omitting a field from /update/sso_settings clears it, which provider switching relies on; the deeper write-path concern that behaviour points at is tracked in LIT-4498.
70 lines
2.3 KiB
YAML
70 lines
2.3 KiB
YAML
name: "Unit Tests: Proxy API Endpoints"
|
|
|
|
on:
|
|
pull_request:
|
|
branches:
|
|
- main
|
|
- litellm_internal_staging
|
|
- litellm_oss_staging
|
|
- "litellm_**"
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
proxy-endpoints:
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
pull-requests: write
|
|
uses: ./.github/workflows/_test-unit-base.yml
|
|
with:
|
|
test-path: >-
|
|
tests/test_litellm/proxy/management_endpoints
|
|
tests/test_litellm/proxy/guardrails
|
|
tests/test_litellm/proxy/management_helpers
|
|
tests/test_litellm/proxy/anthropic_endpoints
|
|
tests/test_litellm/proxy/google_endpoints
|
|
tests/test_litellm/proxy/openai_files_endpoint
|
|
tests/test_litellm/proxy/batches_endpoints
|
|
tests/test_litellm/proxy/video_endpoints
|
|
tests/test_litellm/proxy/response_api_endpoints
|
|
tests/test_litellm/proxy/image_endpoints
|
|
tests/test_litellm/proxy/vector_store_endpoints
|
|
tests/test_litellm/proxy/agent_endpoints
|
|
tests/test_litellm/proxy/a2a
|
|
tests/test_litellm/proxy/discovery_endpoints
|
|
tests/test_litellm/proxy/health_endpoints
|
|
tests/test_litellm/proxy/shutdown
|
|
tests/test_litellm/proxy/public_endpoints
|
|
tests/test_litellm/proxy/prompts
|
|
tests/test_litellm/proxy/rag_endpoints
|
|
tests/test_litellm/proxy/realtime_endpoints
|
|
tests/test_litellm/proxy/ui_crud_endpoints
|
|
tests/test_litellm/proxy/config_resolvers
|
|
tests/test_litellm/proxy/utils
|
|
workers: 2
|
|
reruns: 2
|
|
artifact-name: proxy-endpoints
|
|
|
|
# Behavior-pinning tests for litellm/proxy/proxy_server.py. Owns its
|
|
# own job (not a path on the proxy-endpoints job above) so its budget
|
|
# is independent and its coverage artifact is uploaded separately.
|
|
# See: https://www.notion.so/36c43b8acdab81ee845fd5365128a2fc
|
|
proxy-server:
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
pull-requests: write
|
|
uses: ./.github/workflows/_test-unit-base.yml
|
|
with:
|
|
test-path: tests/test_litellm/proxy/proxy_server
|
|
workers: 4
|
|
reruns: 2
|
|
timeout-minutes: 60
|
|
artifact-name: proxy-server
|