From 290648ce43012a34c0d8f01f7517363dc7d7892c Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sat, 6 Jun 2026 05:10:00 +0000 Subject: [PATCH] fix(auth): guard valid_token None check before passthrough access groups The new passthrough access group lookup added in the access groups PR called valid_token.access_group_ids and assigned valid_token.access_group_passthrough_routes without first checking that valid_token is not None, even though the parameter is typed Optional[UserAPIKeyAuth]. This breaks mypy and would also AttributeError at runtime if the function is ever invoked without a token. Wrap the block in a None check so the new behavior only runs when we actually have a token to attach the resolved routes to. Co-authored-by: Krrish Dholakia --- litellm/proxy/auth/auth_checks.py | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/litellm/proxy/auth/auth_checks.py b/litellm/proxy/auth/auth_checks.py index ecfaee3d65e..9a4befd5b9a 100644 --- a/litellm/proxy/auth/auth_checks.py +++ b/litellm/proxy/auth/auth_checks.py @@ -746,18 +746,19 @@ async def common_checks( # noqa: PLR0915 user_object=user_object, route=route, request_body=request_body ) - passthrough_access_group_ids = list( - { - *(valid_token.access_group_ids or []), - *((team_object.access_group_ids or []) if team_object is not None else []), - } - ) - if passthrough_access_group_ids: - valid_token.access_group_passthrough_routes = ( - await _get_passthrough_routes_from_access_groups( - access_group_ids=passthrough_access_group_ids, - ) + if valid_token is not None: + passthrough_access_group_ids = list( + { + *(valid_token.access_group_ids or []), + *((team_object.access_group_ids or []) if team_object is not None else []), + } ) + if passthrough_access_group_ids: + valid_token.access_group_passthrough_routes = ( + await _get_passthrough_routes_from_access_groups( + access_group_ids=passthrough_access_group_ids, + ) + ) _is_route_allowed = _is_api_route_allowed( route=route,