litellm/tests/unit/test_add_deployment_no_master_key.py
yuneng-jiang f6882246d4
test: move tests/test_litellm root and small trees into tests/unit (#43186)
* ci: run the unit_selection.sh shard files on every event instead of only fork pull requests

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* ci: rename fork-flag to unit-flag now that it applies on every event

* test: move tests/test_litellm root and small trees into tests/unit

Pure renames, no content changes. Follow-up commits in this PR fix
references, merge the three files that already existed in tests/unit,
keep live-provider tests in tests/test_litellm and wire CI.

* test: carry tests/test_litellm conftest isolation into tests/unit

Callback lists, routing fallbacks, cached HTTP clients, logger state, AWS,
proxy-URL and keychain env, and session-end client cleanup now reset for
unit tests too. The environment isolation owns its MonkeyPatch so a test's
own monkeypatch is undone before the model-cost teardown runs.

* test: merge, split and prune the moved root and small-tree tests

Merge batches/test_batch_utils.py and the chat_completions and messages
dispatch tests into the files that already existed in tests/unit. Keep
the live Gemini interactions tests, the async image-fetch format test and
the OpenAI embedding scorer test in tests/test_litellm since they need
real network or keys. Put test_router.py under tests/unit/test_router so
the existing package no longer shadows it. Delete eight tests the audit
found superseded by stronger ones kept in this move.

* ci: run the moved root and small-tree tests under their legacy flags

Add the misc and responses-caching-types flags to unit_selection.sh and
CircleCI, extend enterprise-routing and mcp-integration, and point the
legacy GHA shards, Makefile, redis-compat workflow, merge smoke manifest
and change classifier at the new paths.

* test: make the new tests/unit directories packages

tests/unit/test_package_layout.py requires every directory to carry an
__init__.py, and without one the moved and retained
test_litellm_responses_bridge.py modules collide on import.

* test: scope the unit socket block to tests/unit in shared sessions

The GHA shards collect the legacy test-path and the unit selection in one
pytest session. The unit conftest's loopback-only block leaked into legacy
modules that reach the network at import. The legacy conftest now lifts the
restriction at collect and setup time, and the unit conftest re-applies it
when collecting its own modules.

* test: give the shard-script tests their own GITHUB_OUTPUT

They only passed where the runner set it. The CircleCI unit job's env
allowlist drops it, so the script's redirect failed there.

* test: point the router and module-deletion checks at tests/unit

router_code_coverage and code_qa_check_tests only searched tests/test_litellm,
so the moved router tests no longer counted. The two silent-experiment tests
the audit deleted were the only direct callers of those methods; they are
replaced with tests that assert the forwarded shadow request and the
recursion guard.

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-25 11:30:43 -07:00

140 lines
5 KiB
Python

"""
Test that add_deployment works without master_key set.
This test verifies the fix for the bug where saving LLM spend logs
failed when master_key was None. [https://github.com/BerriAI/litellm/issues/16428]
"""
import os
from unittest.mock import AsyncMock, MagicMock, patch
import pytest
import litellm
from litellm.proxy.proxy_server import ProxyConfig
from litellm.proxy.utils import PrismaClient, ProxyLogging
@pytest.mark.asyncio
async def test_add_deployment_without_master_key():
"""
Test that add_deployment() works when master_key is None.
This should not raise an exception anymore after the fix.
Previously, it would raise: "Master key is not initialized or formatted"
"""
# Set master_key to None
with patch("litellm.proxy.proxy_server.master_key", None):
# Mock the required dependencies
mock_prisma_client = MagicMock(spec=PrismaClient)
mock_prisma_client.db = MagicMock()
mock_prisma_client.db.litellm_config = MagicMock()
mock_prisma_client.db.litellm_config.find_first = AsyncMock(return_value=None)
mock_proxy_logging = MagicMock(spec=ProxyLogging)
# Create ProxyConfig instance
proxy_config = ProxyConfig()
# Mock the internal methods to avoid actual DB calls
proxy_config._should_load_db_object = MagicMock(return_value=False)
proxy_config._init_non_llm_objects_in_db = AsyncMock()
# This should NOT raise an exception
try:
await proxy_config.add_deployment(
prisma_client=mock_prisma_client,
proxy_logging_obj=mock_proxy_logging,
)
# If we get here, the test passed
assert True
except ValueError as e:
if "Master key is not initialized" in str(e):
pytest.fail(f"add_deployment raised ValueError about master_key: {e}")
raise
except Exception as e:
if "Master key is not initialized" in str(e):
pytest.fail(f"add_deployment raised exception about master_key: {e}")
raise
@pytest.mark.asyncio
async def test_add_deployment_without_salt_key_or_master_key(monkeypatch):
"""
Test that add_deployment() works when both master_key and LITELLM_SALT_KEY are None.
This tests the scenario where the user runs proxy without any encryption keys,
such as in a local/dev environment or when just saving spend logs.
"""
# Remove LITELLM_SALT_KEY from environment
monkeypatch.delenv("LITELLM_SALT_KEY", raising=False)
# Set master_key to None
with patch("litellm.proxy.proxy_server.master_key", None):
# Mock the required dependencies
mock_prisma_client = MagicMock(spec=PrismaClient)
mock_prisma_client.db = MagicMock()
mock_prisma_client.db.litellm_config = MagicMock()
mock_prisma_client.db.litellm_config.find_first = AsyncMock(
return_value=None
)
mock_proxy_logging = MagicMock(spec=ProxyLogging)
# Create ProxyConfig instance
proxy_config = ProxyConfig()
# Mock the internal methods
proxy_config._should_load_db_object = MagicMock(return_value=False)
proxy_config._init_non_llm_objects_in_db = AsyncMock()
# This should NOT raise an exception
try:
await proxy_config.add_deployment(
prisma_client=mock_prisma_client,
proxy_logging_obj=mock_proxy_logging,
)
assert True
except ValueError as e:
if "Master key is not initialized" in str(
e
) or "Encryption key is not initialized" in str(e):
pytest.fail(
f"add_deployment raised ValueError about encryption key: {e}"
)
raise
except Exception as e:
if "Master key is not initialized" in str(
e
) or "Encryption key is not initialized" in str(e):
pytest.fail(
f"add_deployment raised exception about encryption key: {e}"
)
raise
def test_add_deployment_sync_without_master_key():
"""
Test that _add_deployment() (sync version) works when master_key is None.
This tests the internal method used by add_deployment().
"""
# Set master_key to None
with patch("litellm.proxy.proxy_server.master_key", None):
with patch("litellm.proxy.proxy_server.llm_router", None):
# Create ProxyConfig instance
proxy_config = ProxyConfig()
# Call _add_deployment with empty model list
# This should NOT raise an exception
try:
result = proxy_config._add_deployment(db_models=[])
# Should return 0 because llm_router is None
assert result == 0
except Exception as e:
if "Master key is not initialized" in str(e):
pytest.fail(
f"_add_deployment raised exception about master_key: {e}"
)
raise