sgl-project--sglang
94057c3d3e
PR Test (NPU) / check-changes (push) Has been cancelled
PR Test (NPU) / pr-gate (push) Has been cancelled
PR Test (NPU) / set-image-config (push) Has been cancelled
PR Test (NPU) / stage-b-test-1-npu-a2 (0) (push) Has been cancelled
PR Test (NPU) / stage-b-test-1-npu-a2 (1) (push) Has been cancelled
PR Test (NPU) / stage-b-test-2-npu-a2 (0) (push) Has been cancelled
PR Test (NPU) / stage-b-test-2-npu-a2 (1) (push) Has been cancelled
PR Test (NPU) / stage-b-test-4-npu-a3 (push) Has been cancelled
PR Test (NPU) / stage-b-test-16-npu-a3 (push) Has been cancelled
PR Test (NPU) / multimodal-gen-test-1-npu-a3 (push) Has been cancelled
PR Test (NPU) / multimodal-gen-test-2-npu-a3 (push) Has been cancelled
PR Test (Arm64) / pr-gate (push) Has been cancelled
PR Test (Arm64) / check-changes (push) Has been cancelled
PR Test (Arm64) / build-test (push) Has been cancelled
PR Test (sgl-router) / gate (push) Has been cancelled
PR Test (sgl-router) / tier-1 — lint (push) Has been cancelled
PR Test (sgl-router) / tier-2 — build + test (push) Has been cancelled
PR Test (sgl-router) / tier-3 — docker (placeholder) (push) Has been cancelled
PR Test (sgl-router) / tier-3 — k8s integration (push) Has been cancelled
PR Test (sgl-router) / tier-3 — e2e (push) Has been cancelled
PR Test (sgl-router) / finish (push) Has been cancelled
PR Test (NPU) / single-node-poc (map[name:qwen3_6_27b_w8a8_1p_in64k_out1k_50ms runner:linux-aarch64-a3-2 test_case:test/registered/ascend/performance/qwen3_6_27b/test_npu_qwen3_6_27b_w8a8_1p_in64k_out1k_50ms.py test_type:perf]) (push) Has been cancelled
PR Test (NPU) / pr-test-npu-finish (push) Has been cancelled
PR Test (Xeon) / pr-gate (push) Has been cancelled
PR Test (Xeon) / check-changes (push) Has been cancelled
PR Test (Xeon) / build-test (, xeon-gnr, base-b-test-cpu) (push) Has been cancelled
PR Test (XPU) / check-changes (push) Has been cancelled
PR Test (XPU) / pr-gate (push) Has been cancelled
PR Test (XPU) / stage-a-test-1-gpu-xpu (push) Has been cancelled
PR Test (XPU) / wait-for-stage-a (push) Has been cancelled
PR Test (XPU) / stage-b-test-1-gpu-xpu (push) Has been cancelled
PR Test (XPU) / finish (push) Has been cancelled
CI Model Inventory / build-inventory (push) Has been cancelled
Lint / lint (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark Compilation Check (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark - Manual Policy (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark - Request Processing (push) Has been cancelled
PR Benchmark (SMG Components) / Benchmark Summary (push) Has been cancelled
PR Test (SMG) / build-wheel (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on windows (x86_64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on macos (x86_64 - auto) (push) Has been cancelled
PR Test (SMG) / python-unit-tests (push) Has been cancelled
PR Test (SMG) / unit-tests (push) Has been cancelled
PR Test (SMG) / benchmarks (push) Has been cancelled
PR Test (SMG) / chat-completions (push) Has been cancelled
PR Test (SMG) / chat-completions-4gpu (push) Has been cancelled
PR Test (SMG) / e2e (push) Has been cancelled
PR Test (SMG) / docker-build-test (push) Has been cancelled
PR Test (SMG) / k8s-integration (push) Has been cancelled
PR Test (SMG) / finish (push) Has been cancelled
PR Test (SMG) / summarize-benchmarks (push) Has been cancelled
Release SGLang Model Gateway Docker Image / publish (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on macos (aarch64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (aarch64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (x86_64 - auto) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (aarch64 - musllinux_1_1) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / build on linux (x86_64 - musllinux_1_1) (push) Has been cancelled
Release SGLang Model Gateway to PyPI / Build SDist (push) Has been cancelled
Release SGLang Model Gateway to PyPI / Upload to PyPI (push) Has been cancelled
Release SGLang Kernels / build-cu129-matrix (aarch64, 12.9, 3.10, arm-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / build-cu129-matrix (x86_64, 12.9, 3.10, x64-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / release-cu129 (push) Has been cancelled
Release SGLang Kernels / build-cu130-matrix (aarch64, 13.0, 3.10, arm-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / build-cu130-matrix (x86_64, 13.0, 3.10, x64-kernel-build-node) (push) Has been cancelled
Release SGLang Kernels / release-cu130 (push) Has been cancelled
Release SGLang Kernels / build-rocm-matrix (3.10, 700) (push) Has been cancelled
Release SGLang Kernels / build-rocm-matrix (3.10, 720) (push) Has been cancelled
Release SGLang Kernels / release-rocm700 (push) Has been cancelled
Release SGLang Kernels / release-rocm720 (push) Has been cancelled
Release SGLang Kernels / build-musa43 (43, 3.10) (push) Has been cancelled
Release SGLang Kernels / release-musa43 (push) Has been cancelled
298 行
9.4 KiB
Python
298 行
9.4 KiB
Python
"""
|
|
Unit tests for HTTP server admin auth.
|
|
|
|
Usage:
|
|
python3 -m pytest test/registered/unit/utils/test_http_server_auth.py -v
|
|
"""
|
|
|
|
import unittest
|
|
|
|
from sglang.srt.utils.auth import AuthLevel, decide_request_auth
|
|
from sglang.test.ci.ci_register import register_cpu_ci
|
|
|
|
register_cpu_ci(est_time=6, suite="base-a-test-cpu")
|
|
register_cpu_ci(est_time=7, suite="base-c-test-cpu")
|
|
|
|
|
|
class TestHttpServerAdminAuth(unittest.TestCase):
|
|
def _decide(
|
|
self,
|
|
*,
|
|
method: str,
|
|
path: str,
|
|
authorization_header: str | None,
|
|
api_key: str | None,
|
|
admin_api_key: str | None,
|
|
auth_level: AuthLevel,
|
|
):
|
|
return decide_request_auth(
|
|
method=method,
|
|
path=path,
|
|
authorization_header=authorization_header,
|
|
api_key=api_key,
|
|
admin_api_key=admin_api_key,
|
|
auth_level=auth_level,
|
|
)
|
|
|
|
def test_no_keys_configured(self):
|
|
# No keys configured -> NORMAL + ADMIN_OPTIONAL are open (legacy),
|
|
# but ADMIN_FORCE must be rejected (403) explicitly.
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header=None,
|
|
api_key=None,
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header=None,
|
|
api_key=None,
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
|
|
d = self._decide(
|
|
method="POST",
|
|
path="/admin_force_demo",
|
|
authorization_header=None,
|
|
api_key=None,
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
)
|
|
self.assertFalse(d.allowed)
|
|
self.assertEqual(d.error_status_code, 403)
|
|
|
|
def test_api_key_only(self):
|
|
# api_key configured -> NORMAL requires api_key (legacy).
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header=None,
|
|
api_key="user",
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
|
|
# ADMIN_OPTIONAL requires api_key when only api_key is configured.
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer wrong",
|
|
api_key="user",
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
|
|
# ADMIN_FORCE must be rejected even if api_key is configured (403).
|
|
d = self._decide(
|
|
method="POST",
|
|
path="/admin_force_demo",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key=None,
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
)
|
|
self.assertFalse(d.allowed)
|
|
self.assertEqual(d.error_status_code, 403)
|
|
|
|
def test_admin_api_key_only(self):
|
|
# admin_api_key only:
|
|
# - normal endpoints open
|
|
# - optional/force endpoints require admin_api_key
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header="Bearer user",
|
|
api_key=None,
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header=None,
|
|
api_key=None,
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
|
|
# Optional endpoints require admin_api_key when admin_api_key is configured.
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer admin",
|
|
api_key=None,
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer user",
|
|
api_key=None,
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
|
|
d = self._decide(
|
|
method="POST",
|
|
path="/admin_force_demo",
|
|
authorization_header="Bearer admin",
|
|
api_key=None,
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
)
|
|
self.assertTrue(d.allowed)
|
|
|
|
def test_with_both_api_keys(self):
|
|
# both api_key and admin_api_key configured:
|
|
# - normal endpoints require api_key
|
|
# - optional endpoints require admin_api_key (api_key is NOT accepted)
|
|
# - force endpoints require admin_api_key
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="GET",
|
|
path="/v1/models",
|
|
authorization_header="Bearer admin",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.NORMAL,
|
|
).allowed
|
|
)
|
|
# Optional endpoints must require admin_api_key when both keys are configured.
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_optional_demo",
|
|
authorization_header="Bearer admin",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_OPTIONAL,
|
|
).allowed
|
|
)
|
|
self.assertFalse(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_force_demo",
|
|
authorization_header="Bearer user",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
).allowed
|
|
)
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="POST",
|
|
path="/admin_force_demo",
|
|
authorization_header="Bearer admin",
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
).allowed
|
|
)
|
|
|
|
def test_options_is_always_allowed(self):
|
|
# CORS preflight should never be blocked.
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="OPTIONS",
|
|
path="/v1/models",
|
|
authorization_header=None,
|
|
api_key="user",
|
|
admin_api_key="admin",
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
).allowed
|
|
)
|
|
|
|
def test_health_and_metrics_are_always_allowed(self):
|
|
# Health/metrics endpoints are always public by design, regardless of auth level / keys.
|
|
combos = [
|
|
dict(api_key=None, admin_api_key=None),
|
|
dict(api_key="user", admin_api_key=None),
|
|
dict(api_key=None, admin_api_key="admin"),
|
|
dict(api_key="user", admin_api_key="admin"),
|
|
]
|
|
paths_allowed = [
|
|
"/health",
|
|
"/health_generate",
|
|
"/metrics",
|
|
"/metrics/",
|
|
"/metrics/prometheus",
|
|
]
|
|
for keys in combos:
|
|
for path in paths_allowed:
|
|
self.assertTrue(
|
|
self._decide(
|
|
method="GET",
|
|
path=path,
|
|
authorization_header=None,
|
|
api_key=keys["api_key"],
|
|
admin_api_key=keys["admin_api_key"],
|
|
auth_level=AuthLevel.ADMIN_FORCE,
|
|
).allowed,
|
|
msg=f"expected allowed for {path=} with {keys=}",
|
|
)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|