mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-04 02:31:27 +00:00
Authenticate to the gateway with real RS256 JWTs from Keycloak (the IdP in the e2e stack), the way an enterprise fronts the proxy with its identity provider. The suite idempotently provisions a realm with an admin client (token carries the litellm_proxy_admin scope), a team client (token carries a hardcoded team_id claim), and a short-lived client, then asserts: an admin token is allowed on a management route; a team token can call its team's model and is denied a model outside the team's allow-list; a token signed by a key outside the IdP's JWKS is rejected; and a short-lived token flips from accepted to 401 once it expires. Adds a urllib-based Keycloak driver (pydantic-validated boundaries, no requests), a JWTAuthClient, keycloak_env/jwt_client fixtures, KEYCLOAK_* config, and two new other.auth.jwt team-model cells (the three jwt reject/allow cells already existed). Requires a licensed proxy started with enable_jwt_auth + litellm_jwtauth.issuers trusting the Keycloak realm (config block documented in the suite module docstring). Part of LIT-4639. |
||
|---|---|---|
| .. | ||
| conftest.py | ||
| jwt_auth_client.py | ||
| keycloak.py | ||
| management_client.py | ||
| scim_provisioning_client.py | ||
| sso_management_client.py | ||
| test_jwt_auth_e2e.py | ||
| test_management_e2e.py | ||
| test_scim_provisioning_e2e.py | ||
| test_sso_management_e2e.py | ||