litellm/tests/test_litellm/proxy
Ishaan Jaff 66eadfabe4
[Bug] Ensure MCP permissions are enforced when using JWT Auth (#20383)
* fix: enforce team MCP permissions when using JWT authentication

Root cause: When JWT auth was used with teams in groups (via team_ids_jwt_field),
the team's MCP permissions were not being enforced because:

1. The default team_allowed_routes did not include mcp_routes
2. allowed_routes_check() failed for MCP endpoints like /mcp/tools/list
3. find_team_with_model_access() skipped the team due to failed route check
4. team_id was None in UserAPIKeyAuth
5. MCPRequestHandler._get_allowed_mcp_servers_for_team() returned empty list

Fix: Add 'mcp_routes' to the default team_allowed_routes in LiteLLM_JWTAuth.

This ensures that teams can access MCP endpoints by default, allowing the
team's MCP server permissions to be properly enforced.

Added tests:
- test_reproduce_jwt_mcp_enforcement_issue: Reproduces the exact bug scenario
- test_verify_mcp_routes_in_default_team_allowed_routes: Verifies fix
- test_mcp_route_check_passes_for_team: Verifies route check works

Co-authored-by: ishaan <ishaan@berri.ai>

* test: add comprehensive E2E tests for JWT + team MCP permission enforcement

Added tests:
- test_e2e_jwt_team_mcp_permissions_enforced: Full E2E test verifying JWT auth
  with teams in groups properly sets team_id and MCPRequestHandler returns
  the team's MCP servers
- test_e2e_jwt_without_team_no_mcp_servers: Verifies no MCP servers returned
  when JWT has no teams
- test_e2e_jwt_team_mcp_key_intersection: Verifies intersection logic when
  both key and team have MCP permissions (result = intersection)

These tests verify the complete flow:
1. JWT token with team in groups field
2. JWT auth properly sets team_id on UserAPIKeyAuth
3. MCPRequestHandler.get_allowed_mcp_servers() returns team's MCP servers
4. Key/team permission intersection works correctly

Co-authored-by: ishaan <ishaan@berri.ai>

* test: add simple tests for JWT + MCP permission enforcement

Simple, focused tests that validate:
1. test_simple_jwt_mcp_permissions_enforced: JWT user with team gets team's MCP servers
2. test_simple_jwt_no_team_no_mcp_servers: JWT user without team gets no MCP servers
3. test_simple_jwt_team_id_required_for_mcp_permissions: Verifies team_id is required
4. test_jwt_auth_sets_team_id_for_mcp_route: JWT auth sets team_id for MCP routes

These tests directly verify the core MCP permission enforcement logic works
when using JWT authentication with teams.

Co-authored-by: ishaan <ishaan@berri.ai>

* Add test: MCP route without model still returns team_id

Co-authored-by: ishaan <ishaan@berri.ai>

* Add 2 debug logs for JWT+MCP troubleshooting

- handle_jwt.py: Log team route check result (team_id, route, is_allowed)
- user_api_key_auth_mcp.py: Log team_id when looking up MCP permissions

Co-authored-by: ishaan <ishaan@berri.ai>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: ishaan <ishaan@berri.ai>
2026-02-03 19:13:13 -08:00
..
_experimental/mcp_server [Bug] Ensure MCP permissions are enforced when using JWT Auth (#20383) 2026-02-03 19:13:13 -08:00
agent_endpoints [Feat] Use A2A registered agents with /chat/completions (#20362) 2026-02-03 15:25:38 -08:00
anthropic_endpoints
auth remove key blocking 2026-01-31 16:46:17 -08:00
client
common_utils fix: ensure auto-rotation updates existing AWS secret instead of creating new one (#19455) 2026-01-20 18:30:36 -08:00
db
discovery_endpoints
experimental/mcp_server
google_endpoints fix(proxy): handle agent parameter in /interactions endpoint (#19866) 2026-01-27 09:34:58 -08:00
guardrails fix(guardrails): populate applied_guardrails when Model Armor blocks content (#20034) 2026-02-02 18:21:44 +05:30
health_endpoints Fix health endpoints 2026-01-31 12:25:04 -08:00
hooks [Feat] Add async_post_call_response_headers_hook to CustomLogger (#20083) 2026-01-30 12:44:44 -08:00
image_endpoints
management_endpoints allow max_budget reset 2026-02-03 16:32:21 -08:00
management_helpers
middleware
openai_files_endpoint Add litellm metadata correctly for file create 2026-01-29 15:20:31 +05:30
pass_through_endpoints Add /openai_passthrough route for openai passthrough requests: 2026-01-29 16:07:45 +05:30
policy_engine [Feat] New LiteLLM Policy engine - create policies to manage guardrails, conditions - permissions per Key, Team (#19612) 2026-01-22 19:49:53 -08:00
prompts fix(prompts): fix prompt info lookup and delete using correct IDs (#19358) 2026-01-20 12:28:34 -08:00
public_endpoints /public/model_hub health information 2026-01-16 15:36:56 -08:00
response_api_endpoints
spend_tracking Add error_message search in spend logs endpoint 2026-01-28 15:06:31 -08:00
test_configs
ui_crud_endpoints feat: support role_mappings from environment variables (#19498) 2026-01-23 19:54:23 -08:00
vector_store_endpoints test_delete_vector_store_checks_access 2026-01-31 12:05:09 -08:00
__init__.py
conftest.py
test_batch_metadata_none_fix.py
test_caching_routes.py
test_chat_completion_metadata.py fix: propagate JWT auth metadata to OTEL spans (#19627) 2026-01-23 21:21:23 -08:00
test_common_request_processing.py Revert "Merge pull request #18790 from BerriAI/litellm_key_team_routing_3" 2026-01-31 17:58:46 -08:00
test_custom_proxy.py
test_empty_model_list.py Fixing tests and linting 2026-01-21 11:02:39 -08:00
test_enforce_user_param.py
test_fallback_management_endpoints.py Add fallback endpoints support 2026-01-16 10:51:33 +05:30
test_fastapi_offline_routes.py
test_health_check_functions.py
test_litellm_pre_call_utils.py [Feat] UI + Backend - Allow adding policies on Keys/Teams + Viewing on Info panels (#19688) 2026-01-23 19:03:44 -08:00
test_model_id_header_propagation.py
test_proxy_cli.py test_get_default_unvicorn_init_args 2026-01-24 12:59:51 -08:00
test_proxy_server.py Revert "Merge pull request #18790 from BerriAI/litellm_key_team_routing_3" 2026-01-31 17:58:46 -08:00
test_proxy_types.py
test_proxy_utils.py Fix date overflow/division by zero in proxy utils (#19527) 2026-01-21 21:09:57 -08:00
test_response_model_sanitization.py fix(proxy): prevent provider-prefixed model leaks (#19943) 2026-01-28 22:26:38 -08:00
test_route_a2a_models.py [Feat] Use A2A registered agents with /chat/completions (#20362) 2026-02-03 15:25:38 -08:00
test_route_llm_request.py fix: args issue & refactor into helper function to reduce bloat for both(#19441) 2026-01-25 10:21:20 +05:30
test_shared_health_check.py
test_spend_log_cleanup.py feat(proxy): cleanup spend logs cron verification, fix, and docs (#19085) 2026-01-14 22:14:48 +05:30
test_swagger_chat_completions.py Fix Swagger UI path with server_root_path in OpenAPI schema (#18947) 2026-01-14 03:48:43 +05:30
test_team_member_update.py