Fix custom auth docs to match config loading behavior

Greptile correctly flagged that enable_post_custom_auth_checks was documented under general_settings even though the proxy reads it via getattr(litellm, ...) and only populates that attribute from litellm_settings. Leaving the docs as-is would cause operators to place the flag in a config section where it is silently ignored.

This follow-up keeps the PR scope docs-only and corrects the config section placement while preserving the original goal: documenting the interaction between the outer post-check gate and custom_auth_run_common_checks.

Constraint: Match the current runtime behavior instead of changing auth semantics
Rejected: Leave the flag under general_settings | would document a non-functional config path
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: When auth config flags are read via litellm module attributes, document them under litellm_settings
Tested: Local source-path verification against proxy_server.py and user_api_key_auth.py; PR bot review feedback incorporated
Not-tested: Full docs build / repo test suite in local environment
Related: #25862
Related: #25863
This commit is contained in:
JunghwanNA 2026-04-17 00:53:51 +09:00
parent f62a5ae84e
commit 370f4a21d1
2 changed files with 5 additions and 3 deletions

View file

@ -185,6 +185,7 @@ router_settings:
| langfuse_default_tags | array of strings | Default tags for Langfuse Logging. Use this if you want to control which LiteLLM-specific fields are logged as tags by the LiteLLM proxy. By default LiteLLM Proxy logs no LiteLLM-specific fields as tags. [Further docs](./logging#litellm-specific-tags-on-langfuse---cache_hit-cache_key) |
| set_verbose | boolean | [DEPRECATED - see debugging docs](./debugging) Use `--debug` or `--detailed_debug` CLI flags, or set `LITELLM_LOG` env var to "INFO", "DEBUG", or "ERROR" instead. |
| json_logs | boolean | If true, logs will be in json format. If you need to store the logs as JSON, just set the `litellm.json_logs = True`. We currently just log the raw POST request from litellm as a JSON [Further docs](./debugging) |
| enable_post_custom_auth_checks | boolean | If true, runs LiteLLM post-custom-auth checks (for example expiry, end-user budget, and model budget checks) on `UserAPIKeyAuth` objects returned by custom auth handlers. Default is false for performance. |
| default_fallbacks | array of strings | List of fallback models to use if a specific model group is misconfigured / bad. [Further docs](./reliability#default-fallbacks) |
| request_timeout | integer | The timeout for requests in seconds. If not set, the default value is `6000 seconds`. [For reference OpenAI Python SDK defaults to `600 seconds`.](https://github.com/openai/openai-python/blob/main/src/openai/_constants.py) |
| force_ipv4 | boolean | If true, litellm will force ipv4 for all LLM requests. Some users have seen httpx ConnectionError when using ipv6 + Anthropic API |
@ -285,7 +286,6 @@ router_settings:
| always_include_stream_usage | boolean | If true, includes usage metrics in every streaming response chunk |
| auto_redirect_ui_login_to_sso | boolean | If true, automatically redirects UI login page to SSO provider |
| control_plane_url | string | URL of the control plane for cross-instance state sharing |
| enable_post_custom_auth_checks | boolean | If true, runs LiteLLM post-custom-auth checks (for example expiry, end-user budget, and model budget checks) on `UserAPIKeyAuth` objects returned by custom auth handlers. Default is false for performance. |
| custom_auth_run_common_checks | boolean | If true, runs standard auth validation checks alongside custom auth handlers |
| custom_ui_sso_sign_in_handler | string | Custom handler for SSO sign-in logic in the UI |
| database_connection_pool_timeout | integer | Database connection pool timeout in seconds |

View file

@ -232,12 +232,14 @@ general_settings:
### Optional: run LiteLLM's post-custom-auth checks
If your custom auth function returns a `UserAPIKeyAuth` object and you want LiteLLM to run the built-in checks on that object, enable the following flags in `general_settings`:
If your custom auth function returns a `UserAPIKeyAuth` object and you want LiteLLM to run the built-in checks on that object, enable the following flags in `litellm_settings` and `general_settings`:
```yaml
litellm_settings:
enable_post_custom_auth_checks: true # opt in to LiteLLM post-auth checks
general_settings:
custom_auth: custom_auth.user_api_key_auth
enable_post_custom_auth_checks: true # opt in to LiteLLM post-auth checks
custom_auth_run_common_checks: true # optional: also run standard model access checks
```