mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
Slice 5 of the management-endpoints behavior-pinning effort. Adds the ``scratch`` function-scoped fixture: each test gets a uuid4-derived namespace prefix, tags writes with it (``key_alias``, ``team_alias``, ``user_id``, ``budget_id``), and the fixture teardown ``delete_many``-s any row whose namespace column starts with that prefix. Cleanup uses Prisma model methods only (no raw SQL, per CLAUDE.md) and orders deletes children-before-parents to avoid FK conflicts. The Slice 3 de-risk smoke is migrated onto the same fixture so it stops accumulating untagged tokens across repeated local runs. Smoke proves both halves of the contract: one test writes a scratch-tagged key and asserts it lands; a second test runs after the first's teardown and asserts no rows in the scratch namespace survived. Plan: https://www.notion.so/36643b8acdab8128a581ced0f6a4744d
47 lines
1.6 KiB
Python
47 lines
1.6 KiB
Python
"""Smoke tests proving the harness boots and talks to the proxy app."""
|
|
|
|
import pytest
|
|
|
|
from .conftest import MASTER_KEY
|
|
|
|
pytestmark = pytest.mark.asyncio(loop_scope="session")
|
|
|
|
|
|
async def test_liveliness(proxy_client):
|
|
resp = await proxy_client.get("/health/liveliness")
|
|
assert resp.status_code == 200
|
|
|
|
|
|
async def test_key_generate_lands_in_db(proxy_client, prisma, scratch):
|
|
"""De-risk gate: prove the harness exercises the full stack end-to-end.
|
|
|
|
A successful ``/key/generate`` requires:
|
|
* the FastAPI lifespan ran (``proxy_startup_event``),
|
|
* ``prisma_client`` connected,
|
|
* ``user_api_key_auth`` accepted the master key,
|
|
* the real ``generate_key_helper_fn`` wrote a hashed row to
|
|
``LiteLLM_VerificationToken``.
|
|
|
|
The scratch fixture tags the row with its prefix so the per-test teardown
|
|
cleans it up — keeps the proxy DB free of accumulated cruft on repeated
|
|
local runs.
|
|
"""
|
|
from litellm.proxy.utils import hash_token
|
|
|
|
resp = await proxy_client.post(
|
|
"/key/generate",
|
|
headers={"Authorization": f"Bearer {MASTER_KEY}"},
|
|
json={"key_alias": scratch.prefix},
|
|
)
|
|
assert resp.status_code == 200, resp.text
|
|
body = resp.json()
|
|
cleartext_key = body["key"]
|
|
assert cleartext_key.startswith("sk-")
|
|
|
|
hashed = hash_token(cleartext_key)
|
|
row = await prisma.db.litellm_verificationtoken.find_unique(where={"token": hashed})
|
|
assert row is not None, "Generated key did not land in LiteLLM_VerificationToken"
|
|
assert row.token == hashed
|
|
assert (
|
|
row.token != cleartext_key
|
|
), "Cleartext token stored — credential boundary broken"
|