litellm/tests/local_testing
Shivam Rawat dc4f5b12ef
fix(proxy): enforce allowed_passthrough_routes for auth=true pass-thr… (#29256)
* fix(proxy): enforce allowed_passthrough_routes for auth=true pass-through

Pass-through endpoints with auth=true were injected into openai_routes,
so teams with openai_routes access bypassed per-team allowed_passthrough_routes.
Gate auth-enforced pass-through at JWT, virtual-key, and non-admin route checks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(proxy): clarify JWT passthrough denial

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(proxy): make pass-through auth checks method-aware

Prevent allowlist bypass when the same path is registered with different auth settings per HTTP method.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix passthrough route auth checks

* fix(proxy): reject unregistered pass-through HTTP methods

Enforce method-aware JWT checks and return 405 when stale FastAPI routes accept requests outside the current pass-through registry.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(proxy): remove duplicate request_method in JWT team lookup

Fixes SyntaxError on proxy startup caused by passing request_method twice to find_team_with_model_access.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix passthrough route auth enforcement

* fix(proxy): raise passthrough-specific 403 directly in virtual-key path

* fix(proxy): load team for RBAC role-claim JWT passthrough gating

* Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326)

This reverts the Bedrock CI account migration (#28728). The original account
(888602223428) was put under an AWS security restriction after a leaked key
and has since been reactivated, while the replacement account (941277531214)
lacks access to several models the suites exercise (legacy Bedrock Claude 3
models, Cohere, Nova Canvas image gen, Bedrock batch inference, and flagship
Opus). Pointing CI back at the reactivated account restores that coverage.

This is the exact inverse of #28728: all hardcoded 941277531214 references go
back to 888602223428 (provisioned/imported-model ARNs, AgentCore runtime ARNs
and their suffixes, batch execution role ARN, and the example proxy config),
the S3 buckets revert to litellm-proxy and load-testing-oct, the guardrail IDs
revert to wf0hkdb5x07f and ff6ujrregl1q, the SageMaker endpoint and Knowledge
Base revert to their original ids, and the live-call tests go back to the
legacy model strings. The grid_spec fail_reason workaround for the unentitled
Opus cells is dropped while keeping the unrelated bedrock_effort_ceiling field
added after the migration.

The CircleCI AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars still point at
941277531214 and must be set to the reactivated account's fresh credentials
separately via the CircleCI API; AWS_REGION_NAME stays us-west-2.

(cherry picked from commit f11c12d157)

* fix(proxy): scope pass-through 405 to registry routes; grant rerank passthrough in rpm tests

The auth=true pass-through 405 guard fired for mapped provider routes
(e.g. /assemblyai/*) that are not in the in-memory registry, since
get_registered_pass_through_route returns None for them while
is_registered_pass_through_route matches via mapped_pass_through_routes.
Only raise 405 when the path is registered but the request method is not
allowed, so mapped provider pass-throughs fall through to the default
target params as before.

The rpm-limit pass-through tests register /v1/rerank with auth=true but
gave their keys no allowed_passthrough_routes, so the new default-deny
returned 403 before the rate limiter ran (non-deterministically,
depending on registry insertion order). Grant the keys explicit
passthrough access so the tests exercise rate limiting under the new
auth model.

* fix(proxy): guard request method lookup against scopes without a method

Starlette's Request.method property reads scope["method"] and raises
KeyError when the scope omits it (e.g. minimally-constructed test
requests). getattr only swallows AttributeError, so the new
_get_request_method helper propagated the KeyError up through
user_api_key_auth and surfaced as a ProxyException. Catch KeyError
(and AttributeError) and fall back to None.

* test(passthrough): pin SERVER_ROOT_PATH in unregistered-method test

test_custom_proxy.py sets os.environ['SERVER_ROOT_PATH'] = '/my-custom-path'
at module import with no cleanup. When that module is collected into the same
xdist worker as this test, the leaked root path is prepended to registered
pass-through paths, so is_registered_pass_through_route misses '/test/path'
and the handler returns 404 instead of the expected 405 (order-dependent).
Pin SERVER_ROOT_PATH to '' so the test is deterministic.

* test(passthrough): restore regression coverage for non-auth-enforced pass-through via llm_api_routes

* fix(proxy): record auth flag in pass-through registry for allowlist enforcement

Auth-enforced pass-through detection inferred enforcement from the FastAPI
dependency stored at registration time. The management create and update
endpoints register routes with dependencies=None even though auth defaults to
true, so is_auth_enforced_pass_through_route treated those DB-created routes as
unenforced. A key allowed for llm_api_routes could then call a management-created
auth-enabled pass-through route without matching allowed_passthrough_routes.

Store the auth setting on each registry entry and read it directly when deciding
whether the allowlist applies, instead of deriving it from dependency metadata.

* fix(proxy): include bool in pass-through registry value type for auth flag

The auth flag stored in _registered_pass_through_routes is a bool, which
was not part of the registry value Union, so mypy rejected the dict literal.
Add bool to the Union and narrow route_methods to a list before the
membership check so the in-operator stays valid.

* fix(proxy): preserve stored auth flag on pass-through endpoint update

model_dump(exclude_none=True) re-included the auth=True default whenever
a partial update omitted auth, silently flipping an existing auth=false
pass-through to auth-enforced and 403ing every team/key without
allowed_passthrough_routes. Merge only explicitly set fields via
exclude_unset so omitted fields keep their stored value.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: mateo-berri <277851410+mateo-berri@users.noreply.github.com>
2026-05-30 17:07:24 -07:00
..
.litellm_cache
auto_router
example_config_yaml test: test 2026-03-28 19:17:38 -07:00
test_configs test: test 2026-03-28 19:17:38 -07:00
test_model_response_typing
azure_fine_tune.jsonl
azure_speech.mp3
batch_job_results_furniture.jsonl
cache_unit_tests.py
conftest.py fix(tests/vcr): make Redis cassette cache replay deterministically (zero VCR misses on consecutive runs) (#28826) 2026-05-26 11:30:44 -07:00
create_mock_standard_logging_payload.py chore(ci): modernize model references in tests and configs (#27856) 2026-05-15 15:44:28 -07:00
data_map.txt
eagle.wav
example.jsonl
gettysburg.wav
large_text.py
model_cost.json
openai_batch_completions_router.jsonl
openai_batch_completions.jsonl
speech_vertex.mp3
stream_chunk_testdata.py
test_acompletion_fallbacks.py
test_acompletion.py
test_acooldowns_router.py test: test 2026-03-28 19:17:38 -07:00
test_add_function_to_prompt.py
test_add_update_models.py fix(tests): skip remaining real prisma DB tests in CI and related test suites 2026-02-20 13:25:42 -03:00
test_aim_guardrails.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_alangfuse.py test: update key names 2026-03-28 21:13:16 -07:00
test_amazing_vertex_completion.py test(vertex_ai): tolerate transient 500 in google maps grounding test (#28503) 2026-05-21 17:01:49 -07:00
test_anthropic_prompt_caching.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_arize_ai.py test: rename env var 2026-03-28 20:27:39 -07:00
test_arize_phoenix.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_assistants.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_async_fn.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_auth_utils.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_azure_anthropic_sync_post.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_azure_content_safety.py
test_azure_openai.py test: test 2026-03-28 19:17:38 -07:00
test_azure_perf.py test: test 2026-03-28 19:17:38 -07:00
test_basic_python_version.py [Test] CI: add v2 migration resolver coverage with local Postgres 2026-04-21 14:40:11 -07:00
test_batch_completion_return_exceptions.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_batch_completions.py replace retired claude-3-haiku-20240307 with claude-haiku-4-5-20251001 in local_testing part1 and router fallback tests 2026-04-20 16:10:45 -07:00
test_blocked_user_list.py fix(tests): skip remaining real prisma DB tests in CI and related test suites 2026-02-20 13:25:42 -03:00
test_braintrust.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_budget_manager.py
test_cache_preset_key.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_caching_handler.py fix(caching): replay openai/responses bridge cache hits as chat streams (#28158) 2026-05-18 16:27:06 -07:00
test_caching_ssl.py Merge main and resolve conflict in test_router_client_init.py 2026-03-30 18:44:33 -07:00
test_caching.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_class.py test: test 2026-03-28 19:17:38 -07:00
test_completion_cost.py test(fireworks): mock remaining live smoke tests 2026-05-15 22:28:27 -07:00
test_completion_with_retries.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_completion.py Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326) 2026-05-30 11:26:24 -07:00
test_config.py test: test 2026-03-28 19:17:38 -07:00
test_cost_calc.py Revert "Fix xdist test isolation: capture true defaults and poll instead of sleep" 2026-03-15 22:57:39 -07:00
test_custom_api_logger.py
test_custom_callback_input.py fix(tests): replace shut-down gpt-4o-audio-preview with gpt-audio-1.5 (#28281) 2026-05-19 14:48:30 -07:00
test_custom_llm.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_custom_logger.py Mark test_redis_cache_completion_stream as flaky with retries 2026-03-15 20:44:18 -07:00
test_disk_cache_unit_tests.py
test_docker_no_network_on_deploy.py build: migrate packaging, CI, and Docker from Poetry to uv (#25007) 2026-04-09 11:46:23 -07:00
test_dual_cache.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_dynamic_rate_limit_handler.py
test_dynamodb_logs.py
test_embedding.py [Test] Tests: Stop parametrizing API keys into pytest test IDs (#27249) 2026-05-05 17:21:18 -07:00
test_exceptions.py fix: cleanup tests 2026-03-30 16:24:35 -07:00
test_file_types.py
test_function_call_parsing.py Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326) 2026-05-30 11:26:24 -07:00
test_function_calling.py Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326) 2026-05-30 11:26:24 -07:00
test_function_setup.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_gcs_bucket.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_gcs_cache_unit_tests.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_gemini_reasoning_content.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_get_llm_provider.py test: drop duplicate openrouter prefix-strip test 2026-04-25 18:06:25 -03:00
test_get_model_file.py Revert "Merge pull request #16590 from Chesars/refactor/remove-backup-file-dry-principle" 2026-04-25 17:10:41 -03:00
test_get_model_info.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_get_optional_params_embeddings.py fix(embeddings): allow dimensions param passthrough via allowed_openai_params for non-text-embedding-3 OpenAI models 2026-02-26 09:59:37 +05:30
test_get_optional_params_functions_not_supported.py
test_google_ai_studio_gemini.py
test_guardrails_ai.py
test_helicone_integration.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_http_parsing_utils.py
test_img_resize.py
test_lakera_ai_prompt_injection.py
test_langchain_ChatLiteLLM.py
test_langsmith.py
test_least_busy_routing.py
test_litellm_max_budget.py
test_llm_guard.py
test_load_test_router_s3.py
test_loadtest_router.py test: test 2026-03-28 19:17:38 -07:00
test_logfire.py
test_logging.py
test_longer_context_fallback.py
test_lowest_cost_routing.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_lowest_latency_routing.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_lunary.py
test_max_tpm_rpm_limiter.py
test_mem_leak.py
test_mem_usage.py
test_mock_request.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_model_alias_map.py fix(test): scope ERROR log assertion to LiteLLM logger in test_model_alias_map 2026-04-29 03:48:41 +00:00
test_model_max_token_adjust.py
test_multiple_deployments.py [Fix] TogetherAIConfig.get_supported_openai_params recursion 2026-04-16 17:20:58 -07:00
test_ollama_local_chat.py
test_ollama_local.py
test_ollama.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_openai_moderations_hook.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_opik.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_pass_through_endpoints.py fix(proxy): enforce allowed_passthrough_routes for auth=true pass-thr… (#29256) 2026-05-30 17:07:24 -07:00
test_profiling_router.py
test_prometheus_service.py [Release Fix] (#22411) 2026-02-28 09:46:35 -08:00
test_prompt_caching.py
test_prompt_injection_detection.py test: test 2026-03-28 19:17:38 -07:00
test_promptlayer_integration.py
test_provider_specific_config.py Litellm fix update bedrock models (#24947) 2026-04-01 19:22:54 -07:00
test_pydantic_namespaces.py
test_pydantic.py
test_redis_batch_optimizations.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_register_model.py Revert "test_update_model_cost_map_url" 2025-12-22 12:41:30 +05:30
test_responses_stream_cache_keys.py fix(cache): persist and replay streamed Responses API requests (#24580) 2026-05-01 11:55:36 +05:30
test_router_auto_router.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_router_batch_completion.py
test_router_budget_limiter.py test: test 2026-03-28 19:17:38 -07:00
test_router_caching.py test: test 2026-03-28 19:17:38 -07:00
test_router_client_init.py test_router_init_azure_service_principal_with_secret_with_environment_variables 2026-03-30 21:15:53 -07:00
test_router_cooldown_handlers.py test: test 2026-03-28 19:17:38 -07:00
test_router_custom_routing.py Optimize CI: parallelize router and guardrails test jobs, fix test isolation 2026-03-14 22:54:44 -07:00
test_router_debug_logs.py feat: routing groups ui 2026-05-04 18:09:14 -07:00
test_router_fallback_handlers.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_router_fallbacks.py replace retired claude-3-haiku-20240307 with claude-haiku-4-5-20251001 in local_testing part1 and router fallback tests 2026-04-20 16:10:45 -07:00
test_router_get_deployments.py Fix:add async_get_available_deployment_for_pass_through in code tests 2026-01-16 16:37:44 +05:30
test_router_max_parallel_requests.py fix(tests/vcr): make Redis cassette cache replay deterministically (zero VCR misses on consecutive runs) (#28826) 2026-05-26 11:30:44 -07:00
test_router_pattern_matching.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_router_retries.py fix(tests): read CI_CD_DEFAULT_ANTHROPIC_MODEL env var instead of hardcoding model (#21781) 2026-02-21 10:46:49 -08:00
test_router_timeout.py Litellm fix update bedrock models (#24947) 2026-04-01 19:22:54 -07:00
test_router_utils.py test: test 2026-03-28 19:17:38 -07:00
test_router_with_fallbacks.py
test_router.py test(vcr): drop dead 'from respx import MockRouter' imports 2026-05-13 00:32:03 +00:00
test_rules.py
test_sagemaker_nova_integration.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_sagemaker.py Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326) 2026-05-30 11:26:24 -07:00
test_scheduler.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_secret_detect_hook.py
test_spend_calculate_endpoint.py
test_stream_chunk_builder.py fix(tests): replace shut-down gpt-4o-audio-preview with gpt-audio-1.5 (#28281) 2026-05-19 14:48:30 -07:00
test_streaming.py Revert "chore(tests): migrate Bedrock CI to AWS account 941277531214 (#28728)" (#29326) 2026-05-30 11:26:24 -07:00
test_supabase_integration.py
test_team_config.py
test_text_completion.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_timeout.py Litellm fix update bedrock models (#24947) 2026-04-01 19:22:54 -07:00
test_together_ai.py
test_tpm_rpm_routing_v2.py fix: drain logging worker in test_router_caching_ttl to remove flake 2026-04-23 14:48:02 -07:00
test_traceloop.py
test_ui_sso_helper_utils.py
test_unit_test_caching.py style: black format test_unit_test_caching.py 2026-04-15 18:19:04 -07:00
test_update_spend.py fix(tests): skip remaining real prisma DB tests in CI and related test suites 2026-02-20 13:25:42 -03:00
test_validate_environment.py
test_wandb.py
user_cost.json
vertex_ai.jsonl
vertex_batch_completions.jsonl
vertex_key.json test: update to new vertex ai keys 2026-03-28 20:19:05 -07:00
whitelisted_bedrock_models.txt Litellm fix update bedrock models (#24947) 2026-04-01 19:22:54 -07:00