mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 20:28:23 +00:00
A positive cost reported by an upstream pre-empted token pricing with no check on who reported it. Because the bearer overrun path settles min(chargeable, total) against the key's balance minus sibling reservations, any configured or chained provider that controls an accepted cost field could bill far beyond the reservation it was authorized against and drain the key. The mirror case bled the operator: an under-reporting provider with omitted token usage settled at its own low number. Reported cost is now honoured only for provider types that opt in via BaseUpstreamProvider.trusts_reported_cost, which defaults to off. A new provider therefore prices from tokens until someone deliberately approves it. PPQ.AI (BYOK — only PPQ knows the user's upstream bill) and OpenRouter (per-request sub-provider routing) are approved; chained Routstr peers and generic/custom rows are not. This is a policy gate, not a clamp: PPQ BYOK legitimately settles above the reservation and still does. The flag is threaded from the serving provider instance through adjust_payment_for_tokens to calculate_cost alongside provider_fee, at every streaming and non-streaming settlement site in the upstream base provider, so the two paths agree. Two supporting changes: - _coerce_usd rejects non-finite input. Infinity previously survived the clamp and reached math.ceil, where the OverflowError was swallowed by the USD path's broad handler — correct by accident. NaN was already folded to zero by max() comparison semantics; it is now explicit. Nothing about int/float msats arithmetic changed, so billing amounts are unaffected. - A trusted provider's cost is compared against what its own reported tokens would have been priced at, and against the reservation. Ratios outside the bounds are logged in both directions. They are not clamped: the legitimate BYOK spread is wide enough that clamping would mis-bill real traffic, so the goal is that a mis-report is visible rather than silent. Existing USD-path tests now declare their provider as cost-reporting; no assertion was changed.
FastAPI Async Unit Tests
This directory contains async unit tests for the Routstr proxy FastAPI application.
Installation
First, ensure you have the development dependencies installed:
uv pip install -e ".[dev]"
Running Tests
To run all tests:
pytest
To run tests with coverage:
pytest --cov=routstr --cov-report=html
To run specific test files:
pytest tests/test_main.py
pytest tests/test_models.py
pytest tests/test_proxy.py
To run only async tests:
pytest -m asyncio
Test Structure
conftest.py- Pytest fixtures and configurationtest_main.py- Tests for main app endpointstest_account.py- Tests for wallet/account management endpointstest_proxy.py- Tests for the proxy functionality with mocked upstreamtest_models.py- Tests for model pricing and data structures
Key Fixtures
async_client- Async HTTP client for testing FastAPI endpointstest_session- In-memory SQLite database session for teststest_api_key- Pre-configured API key with balanceapi_key_with_balance- API key with sufficient balance for proxy tests
Environment Variables
The tests automatically set up required environment variables in conftest.py. No manual configuration needed.
Writing New Tests
- Use
@pytest.mark.asynciofor async tests - Use the provided fixtures for database and client access
- Mock external dependencies (like upstream API calls)
- Test both success and error cases
- Verify database state changes when applicable