项目文件夹

文件
wehub-resource-sync 94057c3d3e
PR Test (NPU) / check-changes (push) Has been cancelled
PR Test (NPU) / pr-gate (push) Has been cancelled
PR Test (NPU) / set-image-config (push) Has been cancelled
PR Test (NPU) / stage-b-test-1-npu-a2 (0) (push) Has been cancelled
PR Test (NPU) / stage-b-test-1-npu-a2 (1) (push) Has been cancelled
PR Test (NPU) / stage-b-test-2-npu-a2 (0) (push) Has been cancelled
PR Test (NPU) / stage-b-test-2-npu-a2 (1) (push) Has been cancelled
PR Test (NPU) / stage-b-test-4-npu-a3 (push) Has been cancelled
PR Test (NPU) / stage-b-test-16-npu-a3 (push) Has been cancelled
PR Test (NPU) / multimodal-gen-test-1-npu-a3 (push) Has been cancelled
PR Test (NPU) / multimodal-gen-test-2-npu-a3 (push) Has been cancelled
PR Test (Arm64) / pr-gate (push) Has been cancelled
PR Test (Arm64) / check-changes (push) Has been cancelled
PR Test (Arm64) / build-test (push) Has been cancelled
PR Test (sgl-router) / gate (push) Has been cancelled
PR Test (sgl-router) / tier-1 — lint (push) Has been cancelled
PR Test (sgl-router) / tier-2 — build + test (push) Has been cancelled
PR Test (sgl-router) / tier-3 — docker (placeholder) (push) Has been cancelled
PR Test (sgl-router) / tier-3 — k8s integration (push) Has been cancelled
PR Test (sgl-router) / tier-3 — e2e (push) Has been cancelled
PR Test (sgl-router) / finish (push) Has been cancelled
PR Test (NPU) / single-node-poc (map[name:qwen3_6_27b_w8a8_1p_in64k_out1k_50ms runner:linux-aarch64-a3-2 test_case:test/registered/ascend/performance/qwen3_6_27b/test_npu_qwen3_6_27b_w8a8_1p_in64k_out1k_50ms.py test_type:perf]) (push) Has been cancelled
PR Test (NPU) / pr-test-npu-finish (push) Has been cancelled
PR Test (Xeon) / pr-gate (push) Has been cancelled
PR Test (Xeon) / check-changes (push) Has been cancelled
PR Test (Xeon) / build-test (, xeon-gnr, base-b-test-cpu) (push) Has been cancelled
PR Test (XPU) / check-changes (push) Has been cancelled
PR Test (XPU) / pr-gate (push) Has been cancelled
PR Test (XPU) / stage-a-test-1-gpu-xpu (push) Has been cancelled
PR Test (XPU) / wait-for-stage-a (push) Has been cancelled
PR Test (XPU) / stage-b-test-1-gpu-xpu (push) Has been cancelled
PR Test (XPU) / finish (push) Has been cancelled
CI Model Inventory / build-inventory (push) Has been cancelled
Lint / lint (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark Compilation Check (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark - Manual Policy (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark - Request Processing (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark Summary (push) Has been cancelled
PR Test (SMG) / build-wheel (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on windows (x86_64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on macos (x86_64 - auto) (push) Has been cancelled
PR Test (SMG) / python-unit-tests (push) Has been cancelled
PR Test (SMG) / unit-tests (push) Has been cancelled
PR Test (SMG) / benchmarks (push) Has been cancelled
PR Test (SMG) / chat-completions (push) Has been cancelled
PR Test (SMG) / chat-completions-4gpu (push) Has been cancelled
PR Test (SMG) / e2e (push) Has been cancelled
PR Test (SMG) / docker-build-test (push) Has been cancelled
PR Test (SMG) / k8s-integration (push) Has been cancelled
PR Test (SMG) / finish (push) Has been cancelled
PR Test (SMG) / summarize-benchmarks (push) Has been cancelled
Release SGLang Model Gateway Docker Image / publish (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on macos (aarch64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (aarch64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (x86_64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (aarch64 - musllinux_1_1) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (x86_64 - musllinux_1_1) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / Build SDist (push) Has been cancelled
Release SGLang Model Gateway to PyPI / Upload to PyPI (push) Has been cancelled
Release SGLang Kernels / build-cu129-matrix (aarch64, 12.9, 3.10, arm-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / build-cu129-matrix (x86_64, 12.9, 3.10, x64-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / release-cu129 (push) Has been cancelled
Release SGLang Kernels / build-cu130-matrix (aarch64, 13.0, 3.10, arm-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / build-cu130-matrix (x86_64, 13.0, 3.10, x64-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / release-cu130 (push) Has been cancelled
Release SGLang Kernels / build-rocm-matrix (3.10, 700) (push) Has been cancelled
Release SGLang Kernels / build-rocm-matrix (3.10, 720) (push) Has been cancelled
Release SGLang Kernels / release-rocm700 (push) Has been cancelled
Release SGLang Kernels / release-rocm720 (push) Has been cancelled
Release SGLang Kernels / build-musa43 (43, 3.10) (push) Has been cancelled
Release SGLang Kernels / release-musa43 (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:38:16 +08:00

298 行
9.4 KiB
Python

"""
Unit tests for HTTP server admin auth.
Usage:
python3 -m pytest test/registered/unit/utils/test_http_server_auth.py -v
"""
import unittest
from sglang.srt.utils.auth import AuthLevel, decide_request_auth
from sglang.test.ci.ci_register import register_cpu_ci
register_cpu_ci(est_time=6, suite="base-a-test-cpu")
register_cpu_ci(est_time=7, suite="base-c-test-cpu")
class TestHttpServerAdminAuth(unittest.TestCase):
def _decide(
self,
*,
method: str,
path: str,
authorization_header: str | None,
api_key: str | None,
admin_api_key: str | None,
auth_level: AuthLevel,
):
return decide_request_auth(
method=method,
path=path,
authorization_header=authorization_header,
api_key=api_key,
admin_api_key=admin_api_key,
auth_level=auth_level,
)
def test_no_keys_configured(self):
# No keys configured -> NORMAL + ADMIN_OPTIONAL are open (legacy),
# but ADMIN_FORCE must be rejected (403) explicitly.
self.assertTrue(
self._decide(
method="GET",
path="/v1/models",
authorization_header=None,
api_key=None,
admin_api_key=None,
auth_level=AuthLevel.NORMAL,
).allowed
)
self.assertTrue(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header=None,
api_key=None,
admin_api_key=None,
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
d = self._decide(
method="POST",
path="/admin_force_demo",
authorization_header=None,
api_key=None,
admin_api_key=None,
auth_level=AuthLevel.ADMIN_FORCE,
)
self.assertFalse(d.allowed)
self.assertEqual(d.error_status_code, 403)
def test_api_key_only(self):
# api_key configured -> NORMAL requires api_key (legacy).
self.assertFalse(
self._decide(
method="GET",
path="/v1/models",
authorization_header=None,
api_key="user",
admin_api_key=None,
auth_level=AuthLevel.NORMAL,
).allowed
)
self.assertTrue(
self._decide(
method="GET",
path="/v1/models",
authorization_header="Bearer user",
api_key="user",
admin_api_key=None,
auth_level=AuthLevel.NORMAL,
).allowed
)
# ADMIN_OPTIONAL requires api_key when only api_key is configured.
self.assertFalse(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer wrong",
api_key="user",
admin_api_key=None,
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
self.assertTrue(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer user",
api_key="user",
admin_api_key=None,
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
# ADMIN_FORCE must be rejected even if api_key is configured (403).
d = self._decide(
method="POST",
path="/admin_force_demo",
authorization_header="Bearer user",
api_key="user",
admin_api_key=None,
auth_level=AuthLevel.ADMIN_FORCE,
)
self.assertFalse(d.allowed)
self.assertEqual(d.error_status_code, 403)
def test_admin_api_key_only(self):
# admin_api_key only:
# - normal endpoints open
# - optional/force endpoints require admin_api_key
self.assertTrue(
self._decide(
method="GET",
path="/v1/models",
authorization_header="Bearer user",
api_key=None,
admin_api_key="admin",
auth_level=AuthLevel.NORMAL,
).allowed
)
self.assertTrue(
self._decide(
method="GET",
path="/v1/models",
authorization_header=None,
api_key=None,
admin_api_key="admin",
auth_level=AuthLevel.NORMAL,
).allowed
)
# Optional endpoints require admin_api_key when admin_api_key is configured.
self.assertTrue(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer admin",
api_key=None,
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
self.assertFalse(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer user",
api_key=None,
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
d = self._decide(
method="POST",
path="/admin_force_demo",
authorization_header="Bearer admin",
api_key=None,
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_FORCE,
)
self.assertTrue(d.allowed)
def test_with_both_api_keys(self):
# both api_key and admin_api_key configured:
# - normal endpoints require api_key
# - optional endpoints require admin_api_key (api_key is NOT accepted)
# - force endpoints require admin_api_key
self.assertTrue(
self._decide(
method="GET",
path="/v1/models",
authorization_header="Bearer user",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.NORMAL,
).allowed
)
self.assertFalse(
self._decide(
method="GET",
path="/v1/models",
authorization_header="Bearer admin",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.NORMAL,
).allowed
)
# Optional endpoints must require admin_api_key when both keys are configured.
self.assertFalse(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer user",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
self.assertTrue(
self._decide(
method="POST",
path="/admin_optional_demo",
authorization_header="Bearer admin",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_OPTIONAL,
).allowed
)
self.assertFalse(
self._decide(
method="POST",
path="/admin_force_demo",
authorization_header="Bearer user",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_FORCE,
).allowed
)
self.assertTrue(
self._decide(
method="POST",
path="/admin_force_demo",
authorization_header="Bearer admin",
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_FORCE,
).allowed
)
def test_options_is_always_allowed(self):
# CORS preflight should never be blocked.
self.assertTrue(
self._decide(
method="OPTIONS",
path="/v1/models",
authorization_header=None,
api_key="user",
admin_api_key="admin",
auth_level=AuthLevel.ADMIN_FORCE,
).allowed
)
def test_health_and_metrics_are_always_allowed(self):
# Health/metrics endpoints are always public by design, regardless of auth level / keys.
combos = [
dict(api_key=None, admin_api_key=None),
dict(api_key="user", admin_api_key=None),
dict(api_key=None, admin_api_key="admin"),
dict(api_key="user", admin_api_key="admin"),
]
paths_allowed = [
"/health",
"/health_generate",
"/metrics",
"/metrics/",
"/metrics/prometheus",
]
for keys in combos:
for path in paths_allowed:
self.assertTrue(
self._decide(
method="GET",
path=path,
authorization_header=None,
api_key=keys["api_key"],
admin_api_key=keys["admin_api_key"],
auth_level=AuthLevel.ADMIN_FORCE,
).allowed,
msg=f"expected allowed for {path=} with {keys=}",
)
if __name__ == "__main__":
unittest.main()