add warning, if no models in assigned access groups

This commit is contained in:
mubashir1osmani 2026-05-14 08:12:38 -04:00
parent b5ea52c6cf
commit 1c889f0e44
No known key found for this signature in database
GPG key ID: AB055FF67D0B4D9A
2 changed files with 17 additions and 4 deletions

View file

@ -2910,6 +2910,14 @@ async def can_key_call_model(
team_id=valid_token.team_id,
object_type="key",
)
verbose_proxy_logger.warning(
"Key has access_group_ids=%s, but those access groups resolved to no model permissions. "
"Denying model=%s for key_alias=%s, team_id=%s.",
key_access_group_ids,
model,
valid_token.key_alias,
valid_token.team_id,
)
raise ProxyException(
message=f"key not allowed to access model. This key has access_group_ids={key_access_group_ids}, but those groups do not grant any models. Tried to access {model}",
type=ProxyErrorTypes.key_model_access_denied,

View file

@ -1250,10 +1250,13 @@ async def test_can_key_call_model_denies_when_access_group_ids_resolve_no_models
access_group_ids=["empty-group"],
)
with patch(
"litellm.proxy.auth.auth_checks._get_models_from_access_groups",
new_callable=AsyncMock,
return_value=[],
with (
patch(
"litellm.proxy.auth.auth_checks._get_models_from_access_groups",
new_callable=AsyncMock,
return_value=[],
),
patch("litellm.proxy.auth.auth_checks.verbose_proxy_logger.warning") as warning,
):
with pytest.raises(ProxyException):
await can_key_call_model(
@ -1262,6 +1265,8 @@ async def test_can_key_call_model_denies_when_access_group_ids_resolve_no_models
valid_token=user_api_key_object,
llm_router=None,
)
warning.assert_called_once()
assert "resolved to no model permissions" in warning.call_args.args[0]
# ---------------------------------------------------------------------------