Team Ai
Datasetpublic

echodict/llama.cpp

version https://git-lfs.github.com/spec/v1 oid sha256:cfc44b7ba25614df70e6b65e3341cae0310163bd32fd31a6b928a542df433faf size 30786

sourceHugging Faceupdated 6mo agoView on Hugging Face
0likes479downloads
test_security.py137 linesDownload Raw Back to unit
1import pytest2from openai import OpenAI3from utils import *4 5server = ServerPreset.tinyllama2()6 7TEST_API_KEY = "sk-this-is-the-secret-key"8 9@pytest.fixture(autouse=True)10def create_server():11    global server12    server = ServerPreset.tinyllama2()13    server.api_key = TEST_API_KEY14 15 16@pytest.mark.parametrize("endpoint", ["/health", "/models"])17def test_access_public_endpoint(endpoint: str):18    global server19    server.start()20    res = server.make_request("GET", endpoint)21    assert res.status_code == 20022    assert "error" not in res.body23 24 25def test_access_static_assets_without_api_key():26    """Static web UI assets should not require API key authentication (issue #21229)"""27    global server28    server.start()29    for path in ["/", "/bundle.js", "/bundle.css"]:30        res = server.make_request("GET", path)31        assert res.status_code == 200, f"Expected 200 for {path}, got {res.status_code}"32 33 34@pytest.mark.parametrize("api_key", [None, "invalid-key"])35def test_incorrect_api_key(api_key: str):36    global server37    server.start()38    res = server.make_request("POST", "/completions", data={39        "prompt": "I believe the meaning of life is",40    }, headers={41        "Authorization": f"Bearer {api_key}" if api_key else None,42    })43    assert res.status_code == 40144    assert "error" in res.body45    assert res.body["error"]["type"] == "authentication_error"46 47 48def test_correct_api_key():49    global server50    server.start()51    res = server.make_request("POST", "/completions", data={52        "prompt": "I believe the meaning of life is",53    }, headers={54        "Authorization": f"Bearer {TEST_API_KEY}",55    })56    assert res.status_code == 20057    assert "error" not in res.body58    assert "content" in res.body59 60 61def test_correct_api_key_anthropic_header():62    global server63    server.start()64    res = server.make_request("POST", "/completions", data={65        "prompt": "I believe the meaning of life is",66    }, headers={67        "X-Api-Key": TEST_API_KEY,68    })69    assert res.status_code == 20070    assert "error" not in res.body71    assert "content" in res.body72 73 74def test_openai_library_correct_api_key():75    global server76    server.start()77    client = OpenAI(api_key=TEST_API_KEY, base_url=f"http://{server.server_host}:{server.server_port}")78    res = client.chat.completions.create(79        model="gpt-3.5-turbo",80        messages=[81            {"role": "system", "content": "You are a chatbot."},82            {"role": "user", "content": "What is the meaning of life?"},83        ],84    )85    assert len(res.choices) == 186 87 88@pytest.mark.parametrize("origin,cors_header,cors_header_value", [89    ("localhost", "Access-Control-Allow-Origin", "localhost"),90    ("web.mydomain.fr", "Access-Control-Allow-Origin", "web.mydomain.fr"),91    ("origin", "Access-Control-Allow-Credentials", "true"),92    ("web.mydomain.fr", "Access-Control-Allow-Methods", "GET, POST"),93    ("web.mydomain.fr", "Access-Control-Allow-Headers", "*"),94])95def test_cors_options(origin: str, cors_header: str, cors_header_value: str):96    global server97    server.start()98    res = server.make_request("OPTIONS", "/completions", headers={99        "Origin": origin,100        "Access-Control-Request-Method": "POST",101        "Access-Control-Request-Headers": "Authorization",102    })103    assert res.status_code == 200104    assert cors_header in res.headers105    assert res.headers[cors_header] == cors_header_value106 107 108@pytest.mark.parametrize(109    "media_path, image_url, success",110    [111        (None,             "file://mtmd/test-1.jpeg",    False), # disabled media path, should fail112        ("../../../tools", "file://mtmd/test-1.jpeg",    True),113        ("../../../tools", "file:////mtmd//test-1.jpeg", True),  # should be the same file as above114        ("../../../tools", "file://mtmd/notfound.jpeg",  False), # non-existent file115        ("../../../tools", "file://../mtmd/test-1.jpeg", False), # no directory traversal116    ]117)118def test_local_media_file(media_path, image_url, success,):119    server = ServerPreset.tinygemma3()120    server.media_path = media_path121    server.start()122    res = server.make_request("POST", "/chat/completions", data={123        "max_tokens": 1,124        "messages": [125            {"role": "user", "content": [126                {"type": "text", "text": "test"},127                {"type": "image_url", "image_url": {128                    "url": image_url,129                }},130            ]},131        ],132    })133    if success:134        assert res.status_code == 200135    else:136        assert res.status_code == 400137