fix(auth): guard valid_token None check before passthrough access groups

The new passthrough access group lookup added in the access groups PR
called valid_token.access_group_ids and assigned valid_token.access_group_passthrough_routes
without first checking that valid_token is not None, even though the
parameter is typed Optional[UserAPIKeyAuth]. This breaks mypy and would
also AttributeError at runtime if the function is ever invoked without
a token.

Wrap the block in a None check so the new behavior only runs when we
actually have a token to attach the resolved routes to.

Co-authored-by: Krrish Dholakia <krrish-berri-2@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-06-06 05:10:00 +00:00
parent c992955648
commit 290648ce43
No known key found for this signature in database

View file

@ -746,18 +746,19 @@ async def common_checks( # noqa: PLR0915
user_object=user_object, route=route, request_body=request_body
)
passthrough_access_group_ids = list(
{
*(valid_token.access_group_ids or []),
*((team_object.access_group_ids or []) if team_object is not None else []),
}
)
if passthrough_access_group_ids:
valid_token.access_group_passthrough_routes = (
await _get_passthrough_routes_from_access_groups(
access_group_ids=passthrough_access_group_ids,
)
if valid_token is not None:
passthrough_access_group_ids = list(
{
*(valid_token.access_group_ids or []),
*((team_object.access_group_ids or []) if team_object is not None else []),
}
)
if passthrough_access_group_ids:
valid_token.access_group_passthrough_routes = (
await _get_passthrough_routes_from_access_groups(
access_group_ids=passthrough_access_group_ids,
)
)
_is_route_allowed = _is_api_route_allowed(
route=route,