Fix JWT auth email domain validation error message

Fixes issue where users with disallowed email domains receive a
generic "user doesn't exist" error instead of a clear message
about the email domain not being allowed.

Changes:
- Add explicit check for valid_user_email before get_user_object
- Raise ProxyException with clear error message when email domain
  is not in the allowed list
- Prevents confusing error message for email domain restrictions

This fixes the test_allow_access_by_email test failure.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
Julio Quinteros Pro 2026-02-14 15:39:39 -03:00
parent d60a832aae
commit 3f4ba9f03f

View file

@ -1066,6 +1066,15 @@ class JWTAuthManager:
f"JWT Auth: Resolved org_alias='{org_alias}' to org_id='{org_object.organization_id}'"
)
# Check if email domain is allowed before attempting to get/create user
if valid_user_email is False:
raise ProxyException(
message=f"Email domain not allowed. User email: {user_email}. Allowed domain: {jwt_handler.litellm_jwtauth.user_allowed_email_domain}",
type=ProxyErrorTypes.auth_error,
param="user_email",
code=403,
)
user_object: Optional[LiteLLM_UserTable] = None
if user_id:
user_object = (