litellm/litellm-rust/crates/secrets/tests/google.rs
devin-ai-integration[bot] 1a58162630
refactor(http): hand out an owned Client and route all providers through the pool (#43245)
* refactor(messages): take the provider client from the injected HTTP pool

The messages route kept its own process-wide reqwest client, so it ignored
ssl_verify, CA bundles, client certs, proxies and every other setting that
litellm-http resolves. The machine now takes the HttpClientPool and the
call's HttpClientConfig, as OCR does, and the bridge passes its shared pool.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(http): hand out an owned Client and move chat, audio and OIDC onto the pool

HttpClientPool now returns litellm_http::Client, a newtype only crates/http
can build, so every provider client carries the resolved TLS, proxy and
timeout settings. Chat completions and audio transcription drop their
process-wide reqwest clients and take the pool and call config like
messages; their 600s ceiling moves to the request. OidcResolver takes its
client instead of building one, and the bridge hands it the pooled one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(secrets): build Google, Azure and CyberArk manager clients from the pool

The native secret managers built bare reqwest clients, so they ignored the
host's TLS and proxy settings. load_native_manager now takes the pool and
the host config and hands each manager a pooled client.

CyberArk's CYBERARK_SSL_VERIFY and CYBERARK_CLIENT_CERT/KEY become an
override on the host config instead of a hand-built client. To express a
certificate and key in separate files, HttpClientConfig::client_certificate
is now a ClientIdentity that is either one PEM or a split pair.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(clippy): only crates/http may build a reqwest client

Fence reqwest::Client, ClientBuilder and the TLS builder methods with
disallowed-types and disallowed-methods so new code takes a
litellm_http::Client from the pool. crates/http is exempt as the one place
clients are built, and testkit as a dev-only installer. Tests move to
litellm_http::Client::plain_for_test or a pooled client.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(secrets-cyberark): keep verifying certificates when the host disables it

Python hands CyberArk its own ssl_verify, which wins over the global
setting, so CYBERARK_SSL_VERIFY unset or true still verifies even when the
host sets ssl_verify false. The pooled client copied the host's Disabled
and would send the API key unverified; fall back to the built-in roots
instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(python-bridge): treat a missing litellm package as no host HTTP settings

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: Yujong Lee <yujong@berri.ai>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-25 18:31:15 -07:00

117 lines
4 KiB
Rust

#![cfg(feature = "google")]
use std::sync::Arc;
#[rstest::rstest]
#[case::missing(404)]
#[case::failure(503)]
#[tokio::test]
async fn google_resolver_distinguishes_absence_from_failure(#[case] status: u16) {
use litellm_secrets::{
Error, FailurePolicy, KeyManagementSettings, OidcResolver, SecretManager,
SecretManagerState, SecretResolver, SecretValue, google::GoogleSecretManager,
};
use wiremock::{Mock, MockServer, ResponseTemplate, matchers::method};
let server = MockServer::start().await;
Mock::given(method("GET"))
.respond_with(ResponseTemplate::new(status))
.expect(1)
.mount(&server)
.await;
let environment: Arc<dyn litellm_core_utils::settings::Lookup + Send + Sync> =
Arc::new(|name: &str| match name {
"VERTEX_AI_API_KEY" => Some("token".into()),
"KEY" => Some("environment".into()),
_ => None,
});
let manager = GoogleSecretManager::with_client(
litellm_http::Client::plain_for_test(),
server.uri().parse().unwrap(),
"project".into(),
environment.clone(),
None,
false,
)
.unwrap();
let state = SecretManagerState::new(
SecretManager::GoogleSecretManager(manager),
KeyManagementSettings::default(),
);
let resolver = SecretResolver::new_python_compatible(
Arc::new(state),
environment,
OidcResolver::new(litellm_http::Client::plain_for_test()),
)
.with_failure_policy(FailurePolicy::Propagate);
let result = resolver.get_secret_str("KEY", None).await;
if status == 404 {
assert!(matches!(result, Err(Error::ManagedSecretMissing)));
} else {
assert!(
matches!(result, Err(Error::Google(litellm_secrets::google::Error::Status(actual))) if actual == status)
);
}
let fallback = resolver
.with_failure_policy(FailurePolicy::EnvironmentFallback)
.get_secret_str("KEY", None)
.await
.unwrap();
assert_eq!(
fallback.as_ref().map(SecretValue::expose),
Some("environment")
);
}
#[tokio::test]
async fn google_handler_requires_canonical_base64_and_preserves_plaintext_whitespace() {
use base64::{Engine, engine::general_purpose::STANDARD};
use google_cloud_kms_v1::client::KeyManagementService;
use litellm_secrets::{
Error, KeyManagementSettings, SecretManager, get_secret_from_manager, google::GoogleKms,
};
use wiremock::{
Mock, MockServer, ResponseTemplate,
matchers::{body_json, path},
};
let server = MockServer::start().await;
let resource = "projects/project/locations/global/keyRings/ring/cryptoKeys/key";
Mock::given(path(format!("/v1/{resource}:decrypt")))
.and(body_json(
serde_json::json!({"ciphertext":STANDARD.encode("encrypted")}),
))
.respond_with(
ResponseTemplate::new(200)
.set_body_json(serde_json::json!({"plaintext":STANDARD.encode(" value\n")})),
)
.expect(1)
.mount(&server)
.await;
let client = KeyManagementService::builder()
.with_endpoint(server.uri())
.with_credentials(google_cloud_auth::credentials::anonymous::Builder::new().build())
.build()
.await
.unwrap();
let manager = SecretManager::GoogleKms(GoogleKms::new(client, resource.into()));
let settings = KeyManagementSettings::default();
let value = get_secret_from_manager(&manager, "KEY", &settings, &|_: &str| {
Some(STANDARD.encode("encrypted"))
})
.await
.unwrap()
.unwrap();
assert_eq!(value.as_str(), Some(" value\n"));
assert!(matches!(
get_secret_from_manager(&manager, "KEY", &settings, &|_: &str| Some(format!(
" {}",
STANDARD.encode("encrypted")
)))
.await,
Err(Error::InvalidCiphertext)
));
assert!(matches!(
get_secret_from_manager(&manager, "KEY", &settings, &|_: &str| None).await,
Err(Error::MissingCiphertext)
));
}