unsloth/tests/studio/install/test_hf_auth.py
Daniel Han a6dc10dad2
Some checks are pending
Core / Core (HF=default + TRL=default) (push) Waiting to run
Core / Core (HF=4.57.6 + TRL<1) (push) Waiting to run
Core / Core (HF=latest + TRL=latest) (push) Waiting to run
Core / llama.cpp build + smoke (push) Waiting to run
Cross-platform parity / parity (macos-latest) (push) Waiting to run
Cross-platform parity / parity (windows-latest) (push) Waiting to run
Lint CI / Source lint (Python + shell + YAML + JSON + safety nets) (push) Waiting to run
MLX CI on Mac M1 / dispatch (push) Waiting to run
Security audit / advisory audit (pip + npm + cargo) (push) Waiting to run
Security audit / pip scan-packages :: extras (push) Waiting to run
Security audit / pip scan-packages :: studio (push) Waiting to run
Security audit / pip scan-packages :: hf-stack (push) Waiting to run
Security audit / npm scan-packages (Studio frontend tarballs) (push) Waiting to run
Security audit / workflow-trigger lint (pull_request_target / cache-poisoning) (push) Waiting to run
Security audit / pytest tests/security (push) Waiting to run
Security audit / npm provenance + new install-script diff (push) Waiting to run
Studio API CI / Studio API & Auth Tests (push) Waiting to run
Backend CI / (Python 3.10) (push) Waiting to run
Backend CI / (Python 3.11) (push) Waiting to run
Backend CI / (Python 3.12) (push) Waiting to run
Backend CI / (Python 3.13) (push) Waiting to run
Backend CI / Repo tests (CPU) (push) Waiting to run
Frontend CI / Frontend build + bundle sanity (push) Waiting to run
Studio GGUF CI / OpenAI, Anthropic API tests (push) Waiting to run
Studio GGUF CI / Tool calling Tests (push) Waiting to run
Studio GGUF CI / JSON, images (push) Waiting to run
Studio load-orchestrator CI / test (push) Waiting to run
Mac Studio API CI / Studio API & Auth Tests (push) Waiting to run
Mac Studio GGUF CI / OpenAI, Anthropic API tests (push) Waiting to run
Mac Studio GGUF CI / Tool calling Tests (push) Waiting to run
Mac Studio GGUF CI / JSON, images (push) Waiting to run
Mac Studio Install Matrix CI / Install + load (macos-26) (push) Waiting to run
Mac Studio Install Matrix CI / Install + load (macos-15-intel) (push) Waiting to run
Mac Studio Install Matrix CI / Install + load (macos-14) (push) Waiting to run
Mac Studio Install Matrix CI / Install + load (macos-15) (push) Waiting to run
Mac Studio Install Matrix CI / Install + load (macos-26-intel) (push) Waiting to run
Mac Studio UI CI / Chat UI Tests (push) Waiting to run
Mac Studio Update CI / Studio Updating Tests (push) Waiting to run
Studio Tauri CI / Tauri Linux debug build (no codesign) (push) Waiting to run
Studio UI CI / Chat UI Tests (push) Waiting to run
Studio Update CI / Studio Updating Tests (push) Waiting to run
Windows Studio API CI / Studio API & Auth Tests (push) Waiting to run
Windows Studio GGUF CI / OpenAI, Anthropic API tests (push) Waiting to run
Windows Studio GGUF CI / Tool calling Tests (push) Waiting to run
Windows Studio GGUF CI / JSON, images (push) Waiting to run
Windows Studio UI CI / Chat UI Tests (push) Waiting to run
Windows Studio Update CI / Studio Updating Tests (push) Waiting to run
Wheel CI / Wheel build + content sanity + import smoke (push) Waiting to run
Reduce and tighten comments and docstrings across the test suite (#6429)
* Reduce and tighten comments and docstrings in tests

Shorten verbose comments and docstrings across the test suite without
changing any test logic. Remove narration that restates the next line,
collapse long module and test docstrings to a single line, and drop banner
separators. Keep regression context (issue and PR references, run ids),
skip reasons, mocking and timing rationale, license headers, lint and type
directives, and commented-out code.

Comments and docstrings only: an AST signature check confirms no code,
assertions, or string literals changed, and the suite byte-compiles cleanly.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2026-06-18 01:07:09 -07:00

107 lines
4.1 KiB
Python

"""HF auth on the llama.cpp prebuilt installer: auth_headers sends HF_TOKEN to huggingface.co only, and a redirect handler strips Authorization on cross-host redirects. Offline."""
import importlib.util
import sys
import urllib.request
from pathlib import Path
from unittest.mock import MagicMock, patch
import pytest
PACKAGE_ROOT = Path(__file__).resolve().parents[3]
_MODULE_PATH = PACKAGE_ROOT / "studio" / "install_llama_prebuilt.py"
_SPEC = importlib.util.spec_from_file_location(
"studio_install_llama_prebuilt_hf_auth", _MODULE_PATH
)
assert _SPEC is not None and _SPEC.loader is not None
mod = importlib.util.module_from_spec(_SPEC)
sys.modules[_SPEC.name] = mod
_SPEC.loader.exec_module(mod)
_TOKEN_VARS = ("GH_TOKEN", "GITHUB_TOKEN", "HF_TOKEN", "HUGGING_FACE_HUB_TOKEN")
HF_URL = "https://huggingface.co/ggml-org/models/resolve/main/tinyllamas/stories260K.gguf"
GH_URL = "https://api.github.com/repos/unslothai/llama.cpp/releases"
def _headers(url, env):
"""Call auth_headers under a fully controlled token environment."""
with patch.dict(mod.os.environ, env, clear = False):
for var in _TOKEN_VARS:
if var not in env:
mod.os.environ.pop(var, None)
return mod.auth_headers(url)
class TestAuthHeaderRouting:
def test_hf_token_sent_to_huggingface(self):
headers = _headers(HF_URL, {"HF_TOKEN": "hf_x"})
assert headers.get("Authorization") == "Bearer hf_x"
def test_hub_token_fallback(self):
headers = _headers(HF_URL, {"HUGGING_FACE_HUB_TOKEN": "hf_y"})
assert headers.get("Authorization") == "Bearer hf_y"
def test_hf_token_not_sent_to_github(self):
headers = _headers(GH_URL, {"HF_TOKEN": "hf_x"})
assert "Authorization" not in headers
def test_hf_token_not_sent_to_other_hosts(self):
headers = _headers("https://cdn-lfs.huggingface.co/x", {"HF_TOKEN": "hf_x"})
assert "Authorization" not in headers
def test_gh_token_not_sent_to_huggingface(self):
headers = _headers(HF_URL, {"GH_TOKEN": "gh_x"})
assert "Authorization" not in headers
def test_gh_token_still_wins_on_github(self):
headers = _headers(GH_URL, {"GH_TOKEN": "gh_x", "HF_TOKEN": "hf_x"})
assert headers.get("Authorization") == "Bearer gh_x"
def test_no_tokens_no_auth(self):
assert "Authorization" not in _headers(HF_URL, {})
def test_validation_model_url_is_hf(self):
assert mod.should_send_hf_auth(mod.TEST_MODEL_URL) is True
class TestCrossHostRedirectStripsAuth:
def _redirect(self, newurl):
req = urllib.request.Request(HF_URL, headers = {"Authorization": "Bearer hf_x"})
handler = mod._CrossHostAuthStrippingRedirectHandler()
return handler.redirect_request(req, None, 302, "Found", {}, newurl)
def test_cross_host_redirect_drops_authorization(self):
new_request = self._redirect("https://cdn-lfs.huggingface.co/signed/blob")
assert new_request is not None
assert "Authorization" not in new_request.headers
assert "Authorization" not in new_request.unredirected_hdrs
def test_same_host_redirect_keeps_authorization(self):
new_request = self._redirect("https://huggingface.co/elsewhere/blob")
assert new_request is not None
assert new_request.headers.get("Authorization") == "Bearer hf_x"
class TestDownloadBytesWiring:
def test_download_bytes_sends_hf_auth(self):
response = MagicMock()
response.__enter__ = lambda s: s
response.__exit__ = lambda s, *a: False
response.headers.get.return_value = None
response.read.side_effect = [b"data", b""]
with (
patch.object(mod._URL_OPENER, "open", return_value = response) as opened,
patch.dict(mod.os.environ, {"HF_TOKEN": "hf_x"}, clear = False),
):
for var in ("GH_TOKEN", "GITHUB_TOKEN"):
mod.os.environ.pop(var, None)
data = mod.download_bytes(HF_URL)
assert data == b"data"
request = opened.call_args.args[0]
assert request.headers.get("Authorization") == "Bearer hf_x"
if __name__ == "__main__":
sys.exit(pytest.main([__file__, "-q"]))