litellm/tests/e2e/ui
devin-ai-integration[bot] 008fcb4fe3
feat(tool-policies): show the user who owns the key that discovered a tool (#43892)
* feat(tool-policies): show the user who owns the key that discovered a tool

GET /v1/tool/list and GET /v1/tool/{tool_name} resolve the discovering key's owner from the verification token and user tables at response time and return it as a nullable user field. The Tool Policies page adds a User column that shows alias, then email, then ID, with the same cell the Virtual Keys page uses. Keys without an owner, deleted owners, and rows without a key hash show no user, and a database failure in the owner lookup keeps the tools listed with user null

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(tool-policies): bound the owner lookup with chunked membership queries

The key-by-token and user-by-id lookups behind the tool rows' user field
put every distinct key hash into one IN list. BaseRepository gains
find_many_in, which runs the repository's chunked membership query and
converts the rows like find_many does, and the owner lookup uses it

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(tool-policies): cover the owner column across the tool routes and the dashboard

Integration cells for the direct, detail and filtered tool routes, owners without alias or email, deleted owners and keys, keyless and unknown-key historical rows, more keys than one membership chunk, repeated reads, two-worker reads during discovery and a failed owner lookup. A Playwright cell drives the bundled Tool Policies page against the live proxy and follows the owner link

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: ryan <ryan@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-10-01 20:34:57 +00:00
..
fixtures feat(tool-policies): show the user who owns the key that discovered a tool (#43892) 2026-10-01 20:34:57 +00:00
helpers fix(ui): surface x-litellm-call-id in Logs search, table and drawer (#42436) 2026-09-30 02:16:56 +00:00
oidc fix(auth): give UI/CLI session tokens their own AES-GCM context and header-safe shape (#43790) 2026-09-29 18:42:24 -07:00
tests feat(tool-policies): show the user who owns the key that discovered a tool (#43892) 2026-10-01 20:34:57 +00:00
constants.ts test(e2e): wait for serving propagation in UI journeys 2026-09-11 10:25:43 -07:00
globalSetup.ts test(e2e/ui): hide the LiteAdmin button in the shared admin session (#43033) 2026-09-24 14:48:35 -07:00
integration.config.ts test: add extension and browser integration contracts 2026-09-16 13:15:53 -07:00
migration.serverRootPath.config.ts fix(e2e/ui): resolve dashboard base URL from env instead of hardcoding localhost (#34739) 2026-07-27 10:19:32 -07:00
migration.serverRootPath.globalSetup.ts test(e2e): move Admin UI Playwright suite to tests/e2e/ui (#34196) 2026-07-22 19:43:10 +00:00
oidcSetup.ts test: bind management E2E callers and isolate JWT actors 2026-09-12 13:29:04 -07:00
package-lock.json test(e2e-ui): check the MCP Tools tab against the upstream's own tools/list (#42397) 2026-09-21 20:35:30 -07:00
package.json test(e2e-ui): check the MCP Tools tab against the upstream's own tools/list (#42397) 2026-09-21 20:35:30 -07:00
playwright.config.ts fix(auth): give UI/CLI session tokens their own AES-GCM context and header-safe shape (#43790) 2026-09-29 18:42:24 -07:00
playwright.oidc.config.ts test: bind management E2E callers and isolate JWT actors 2026-09-12 13:29:04 -07:00
run_e2e.sh refactor(proxy): rename the local development override to dangerously_permit_weak_or_unset_master_key so the name says exactly what it permits 2026-09-19 18:53:14 -07:00
tsconfig.json test(e2e): move Admin UI Playwright suite to tests/e2e/ui (#34196) 2026-07-22 19:43:10 +00:00