FakeTokenExchangeServer

org.llm4s.testkit.FakeTokenExchangeServer
See theFakeTokenExchangeServer companion object

A local identity provider plus a protected API, for testing workload-identity auth without a network: an RFC 8693 token endpoint (Databricks' /oidc/v1/token), Anthropic's jwt-bearer grant, and OpenAI-format and Anthropic-format endpoints (each streaming when the request asks) that accept only the most recently issued token. Tokens are t1, t2, ... in issue order.

Attributes

Companion
object
Graph
Supertypes
class Object
trait Matchable
class Any

Members list

Value members

Concrete methods

def apiAuthorizations: Seq[String]

The Authorization header of every API call, in order.

The Authorization header of every API call, in order.

Attributes

def close(): Unit
def exchanges: Seq[Map[String, String]]

Every token request received, as its form fields (or JSON fields, for the Anthropic grant).

Every token request received, as its form fields (or JSON fields, for the Anthropic grant).

Attributes

def issuedTokens: Seq[String]

The tokens issued so far: t1, t2, ...

The tokens issued so far: t1, t2, ...

Attributes

def rejectNextApiCalls(n: Int): Unit

Answers the next n API calls with 401, whatever token they carry.

Answers the next n API calls with 401, whatever token they carry.

Attributes

def rejectNextApiCalls(n: Int, status: Int): Unit

Answers the next n API calls with status (401, or 403 for a token that is valid but not allowed).

Answers the next n API calls with status (401, or 403 for a token that is valid but not allowed).

Attributes

def setExpiresIn(seconds: Long): Unit

How long the tokens issued from now on say they live; 3600 by default.

How long the tokens issued from now on say they live; 3600 by default.

Attributes

def setSubjectValidator(f: String => Either[String, Unit]): Unit

Decides whether a presented subject token is acceptable; the default accepts anything non-blank.

Decides whether a presented subject token is acceptable; the default accepts anything non-blank.

Attributes

Concrete fields

val baseUrl: String
val refusedBaseUrl: String

This server under a URL that llm4s's workload-identity rules refuse - plain http to a host that is not one of the loopback literals they accept (localhost, 127.x.y.z, [::1]) - but that still reaches it: the IPv4-mapped IPv6 form of 127.0.0.1, which the JVM connects to over IPv4. Configure a baseUrl or tokenUrl with it to prove a refusal happens before any request: a request that went out would show in exchanges or apiAuthorizations.

This server under a URL that llm4s's workload-identity rules refuse - plain http to a host that is not one of the loopback literals they accept (localhost, 127.x.y.z, [::1]) - but that still reaches it: the IPv4-mapped IPv6 form of 127.0.0.1, which the JVM connects to over IPv4. Configure a baseUrl or tokenUrl with it to prove a refusal happens before any request: a request that went out would show in exchanges or apiAuthorizations.

Attributes