From 3af7de42225ef4c7c41289259f7a55ab67fa23f4 Mon Sep 17 00:00:00 2001 From: Ryan Crabbe Date: Fri, 10 Apr 2026 08:55:32 -0700 Subject: [PATCH] retain ui_routes enum alias for JWT config backwards compatibility --- litellm/proxy/_types.py | 26 ++++++++++++++++++++++++++ tests/proxy_unit_tests/test_jwt.py | 2 +- 2 files changed, 27 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/_types.py b/litellm/proxy/_types.py index 364e49e6257..96e221a9ac0 100644 --- a/litellm/proxy/_types.py +++ b/litellm/proxy/_types.py @@ -607,6 +607,32 @@ class LiteLLMRoutes(enum.Enum): ] ) + # Retained for backwards compatibility with JWT auth configs that reference + # "ui_routes" in admin_allowed_routes. Not used by the proxy's own route + # authorization — UI tokens now go through the same RBAC path as API tokens. + ui_routes = [ + "/sso", + "/sso/get/ui_settings", + "/get/ui_settings", + "/login", + "/key/info", + "/config", + "/spend", + "/model/info", + "/v2/model/info", + "/v2/key/info", + "/models", + "/v1/models", + "/global/spend", + "/global/spend/logs", + "/global/spend/keys", + "/global/spend/models", + "/global/spend/tags", + "/global/predict/spend/logs", + "/global/activity", + "/health/services", + ] + info_routes + internal_user_routes = ( [ "/global/activity", diff --git a/tests/proxy_unit_tests/test_jwt.py b/tests/proxy_unit_tests/test_jwt.py index 73f956a6147..9a8d6d37020 100644 --- a/tests/proxy_unit_tests/test_jwt.py +++ b/tests/proxy_unit_tests/test_jwt.py @@ -715,7 +715,7 @@ async def aaaatest_user_token_output( assert team_result.user_id == user_id -@pytest.mark.parametrize("admin_allowed_routes", [None, ["info_routes"]]) +@pytest.mark.parametrize("admin_allowed_routes", [None, ["ui_routes"]]) @pytest.mark.parametrize("audience", [None, "litellm-proxy"]) @pytest.mark.asyncio async def test_allowed_routes_admin(