litellm/tests/test_litellm
Krish Dholakia e00c181f0c
Mcp user permissions (#21462)
* feat(schema.prisma): add object permissions for end users

allows controlling if end user can call specific mcp servers

* feat: cleanup for customer_endpoints support of object permission id

* fix: cleanup str

* feat(customers/): enforce end user can only call allowed mcps - if configured

* docs: document customer/end user object permission usage

* feat: enforce end user permissions on MCP tool calls

This commit implements end user permission enforcement for MCP servers:

1. Always add server prefixes to MCP tool names
   - Removed conditional logic that only added prefixes when multiple servers existed
   - Now always adds server prefix for consistent tool naming across all scenarios
   - Updated 5 locations in server.py (list_tools, get_prompts, get_resources,
     get_resource_templates, get_prompt)

2. Created MCP End User Permission Guardrail Hook
   - New guardrail hook: litellm/proxy/guardrails/guardrail_hooks/mcp_end_user_permission.py
   - Runs on post_call to validate tool calls in LLM responses
   - Extracts MCP server name from tool names (splits on first '-')
   - Checks if end_user_id has permissions for the MCP server
   - Raises GuardrailRaisedException if end user lacks permission
   - Supports both streaming and non-streaming responses

3. Added comprehensive tests
   - Test file: tests/test_litellm/proxy/guardrails/guardrail_hooks/test_mcp_end_user_permission.py
   - Tests cover: authorized/unauthorized tools, non-MCP tools, no end_user scenarios
   - Tests permission checking logic and exception raising

The hook integrates with the existing MCPRequestHandler._get_allowed_mcp_servers_for_end_user
to fetch end user permissions and enforce access control at the response level.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* refactor: remove redundant add_prefix variable assignments

Simplified the code by removing intermediate `add_prefix` variable
assignments and passing `True` directly to function calls since
we now always add server prefixes.

Changes:
- Removed `add_prefix = True` variable assignments in 5 locations
- Changed `add_prefix=add_prefix` to `add_prefix=True` in function calls
- Added inline comments to clarify the behavior

This makes the code more concise and clearer in intent.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* feat(auth_utils.py): support safety_identifier as a valid way of passing the end user id for responses api

* feat(llms): ensure 'tools' is correctly updated for responses api

* fix: fix greptile feedback

* feat: transformation.py

proper responses api tool handling for guardrail translation layer

---------

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-02-18 18:53:59 -08:00
..
a2a_protocol [Fix] A2a Agent Gateway Fixes - A2A agents deployed with localhost/internal URLs in their agent cards (e.g., http://0.0.0.0:8001/) (#20604) 2026-02-06 15:02:34 -08:00
anthropic_interface/exceptions
caching fix(cache): prevent DualCache async batch check-then-act race (#20986) 2026-02-13 18:32:41 +05:30
completion_extras fix(responses-api): return finish_reason='tool_calls' when response.completed contains function_call items (#19745) 2026-02-16 09:19:57 -08:00
containers fix: add missing OpenAI chat completion params to OPENAI_CHAT_COMPLETION_PARAMS (#21360) 2026-02-16 20:31:21 -08:00
enterprise Fixes based on greptile reviews 2026-02-18 12:19:11 +05:30
expected_responses_api_request [Feat] Adds support for server-side compaction on the OpenAI Responses API context_management (#21058) 2026-02-12 10:00:30 -08:00
experimental_mcp_client
google_genai
images
integrations fix(tests): wrap callbacks cleanup in try/finally and resolve merge conflict 2026-02-18 18:50:17 -03:00
interactions
litellm_core_utils fix(token-counter): fix test isolation and encode() return type normalization 2026-02-17 20:07:52 -03:00
llms fix(tests): resolve merge conflict in test_vertex_ai_rerank_transformation.py 2026-02-18 11:31:56 -03:00
passthrough
proxy Mcp user permissions (#21462) 2026-02-18 18:53:59 -08:00
responses Merge pull request #21326 from BerriAI/litellm_oss_staging_02_16_2026 2026-02-18 17:47:57 +05:30
router_strategy fix(router): remove repeated provider parsing in budget limiter hot path (#21043) 2026-02-12 20:05:55 -08:00
router_utils Merge main into affinity_callback and address deployment affinity review feedback 2026-02-18 10:01:11 -06:00
secret_managers Merge pull request #20481 from Harshit28j/litellm_aws_rotation_fix 2026-02-12 09:36:10 +05:30
test_router
types Add pipeline flow builder UI for guardrail policies (#21188) 2026-02-13 20:06:03 -08:00
vector_stores
__init__.py
conftest.py fix(tests): restore disable_aiohttp_transport and force_ipv4 in isolate_litellm_state 2026-02-17 21:18:49 -03:00
log.txt
readme.md
test_a2a_registry_lookup.py [Feat] Use A2A registered agents with /chat/completions (#20362) 2026-02-03 15:25:38 -08:00
test_acompletion_session_reuse_e2e.py
test_add_deployment_no_master_key.py
test_aembedding_session_reuse_e2e.py
test_anthropic_beta_headers_filtering.py Make tests run with local beta header mapping json 2026-02-13 22:31:42 +05:30
test_azure_video_router.py
test_claude_haiku_4_5_config.py
test_claude_opus_4_6_config.py Fix au.anthropic.claude opus 4 6 v1 (#20731) 2026-02-16 14:15:37 -08:00
test_constants.py [Release - 02/10/2026] v1.81.10-nightly 2026-02-10 16:26:30 -08:00
test_container_router.py
test_cost_calculation_log_level.py fix(proxy): fix master key rotation Prisma validation errors (#21330) 2026-02-16 15:13:05 -08:00
test_cost_calculator.py Fix Bedrock service_tier cost propagation (#21172) 2026-02-16 20:30:10 -08:00
test_deepseek_model_metadata.py fix(model-info): sync DeepSeek model metadata and add bare-name fallback (#20885) 2026-02-11 12:48:10 +05:30
test_eager_tiktoken_load.py
test_exception_exports.py fix: export PermissionDeniedError from litellm.__init__ 2026-02-11 13:39:19 +01:00
test_exception_header_preservation.py
test_exception_mapping_request_attribute.py
test_filter_out_litellm_params.py
test_gpt_image_cost_calculator.py
test_groq_streaming_encoding.py
test_lazy_imports.py
test_logging.py fix:Parse embedded JSON in the message field of logs (#20366) 2026-02-10 16:13:33 +05:30
test_lowest_latency_zero_tokens.py
test_main.py Fix : test_video_content_handler_uses_get_for_openai 2026-02-17 20:06:08 +05:30
test_model_param_helper.py
test_model_response_normalization.py
test_nested_drop_params.py
test_redis.py
test_responses_api_bridge_non_stream.py
test_responses_id_security.py
test_router_google_genai.py
test_router_model_cost_isolation.py [Fix] prevent shared backend model key from being polluted by per-deployment custom pricing (#20679) 2026-02-09 19:38:44 -08:00
test_router_per_deployment_num_retries.py
test_router_redis_init.py
test_router_silent_experiment.py
test_router.py fix(router): propagate model-level tags from config to SpendLogs (#20769) 2026-02-10 15:52:52 -08:00
test_service_logger.py fix(proxy): fix master key rotation Prisma validation errors (#21330) 2026-02-16 15:13:05 -08:00
test_shared_session_integration.py
test_ssl_verify_unit.py BUMP Enterprise PIP 2026-02-14 13:40:48 -08:00
test_system_message_format_bug.py
test_utils.py fix(tests): add inference_geo to model prices JSON schema 2026-02-18 11:29:31 -03:00
test_uuid_helper.py
test_video_generation.py Fix : test_video_content_handler_uses_get_for_openai 2026-02-17 20:06:08 +05:30
test_xai_responses_auto_routing.py

Testing for litellm/

This directory 1:1 maps the the litellm/ directory, and can only contain mocked tests.

The point of this is to:

  1. Increase test coverage of litellm/
  2. Make it easy for contributors to add tests for the litellm/ package and easily run tests without needing LLM API keys.

File name conventions

  • litellm/proxy/test_caching_routes.py maps to litellm/proxy/caching_routes.py
  • test_<filename>.py maps to litellm/<filename>.py