From 205a563b65d179063ea90128081a0676f75235c2 Mon Sep 17 00:00:00 2001 From: v0rtex20k <55466324+v0rtex20k@users.noreply.github.com> Date: Fri, 28 Nov 2025 01:10:19 -0500 Subject: [PATCH] Allow wildcard routes for nonproxy admin (SCIM) (#17178) * checked for wildcards in nonproxy * ready --- litellm/proxy/auth/route_checks.py | 6 ++++ .../proxy/auth/test_route_checks.py | 28 +++++++++++++++++++ 2 files changed, 34 insertions(+) diff --git a/litellm/proxy/auth/route_checks.py b/litellm/proxy/auth/route_checks.py index 664b8a9ddce..76621e95cd3 100644 --- a/litellm/proxy/auth/route_checks.py +++ b/litellm/proxy/auth/route_checks.py @@ -241,6 +241,12 @@ class RouteChecks: route_allowed = True break + if RouteChecks._route_matches_wildcard_pattern( + route=route, pattern=allowed_route + ): + route_allowed = True + break + if not route_allowed: RouteChecks._raise_admin_only_route_exception( user_obj=user_obj, route=route diff --git a/tests/test_litellm/proxy/auth/test_route_checks.py b/tests/test_litellm/proxy/auth/test_route_checks.py index b2a51de3d67..de2aa2427ca 100644 --- a/tests/test_litellm/proxy/auth/test_route_checks.py +++ b/tests/test_litellm/proxy/auth/test_route_checks.py @@ -732,3 +732,31 @@ def test_videos_route_with_virtual_key_llm_api_routes(): assert ( result is True ), f"Virtual key with llm_api_routes should be able to access {route}" + +def test_non_proxy_admin_wildcard_allowed_routes(): + """Test that nonproxy admin users can still use wildcard routes""" + + user_obj = LiteLLM_UserTable( + user_id="test_user", + user_email="test@example.com", + user_role=LitellmUserRoles.INTERNAL_USER.value, + ) + + valid_token = UserAPIKeyAuth( + user_id="test_user", + user_role=LitellmUserRoles.INTERNAL_USER.value, + allowed_routes=["/scim/*"], + ) + + request = MagicMock(spec=Request) + request.query_params = {} + + RouteChecks.non_proxy_admin_allowed_routes_check( + user_obj=user_obj, + _user_role=LitellmUserRoles.INTERNAL_USER.value, + route="/scim/v2/Users", + request=request, + valid_token=valid_token, + request_data={}, + ) +