fix(proxy): allow non-admin users to access pass-through subpath routes with auth

When a pass-through endpoint has both auth=true and include_subpath=true,
non-admin users got 401 errors on subpath requests because only the base
path was registered in openai_routes. Now the wildcard path is also
registered so the auth check recognizes subpath requests as LLM API routes.

Also fixes pre-existing pyright error where logging_obj was possibly
unbound in the except block.
This commit is contained in:
Sameer Kankute 2026-03-19 09:28:55 +05:30
parent 0ecced9780
commit 4829de6102
2 changed files with 45 additions and 0 deletions

View file

@ -651,6 +651,7 @@ async def pass_through_request( # noqa: PLR0915
_parsed_body: Optional[dict] = None
# kwargs for pass through endpoint, contains metadata, litellm_params, call_type, litellm_call_id, passthrough_logging_payload
kwargs: Optional[dict] = None
logging_obj: Optional[Logging] = None
#########################################################
try:
@ -2262,6 +2263,12 @@ async def initialize_pass_through_endpoints(
# Add wildcard route for sub-paths
if endpoint.get("include_subpath", False) is True:
# Register wildcard path in openai_routes so non-admin users
# can access subpath routes when auth is enabled
if _auth is not None and str(_auth).lower() == "true":
_wildcard_path = _path.rstrip("/") + "/*"
if _wildcard_path not in LiteLLMRoutes.openai_routes.value:
LiteLLMRoutes.openai_routes.value.append(_wildcard_path)
InitPassThroughEndpointHelpers.add_subpath_route(
app=app,
path=_path,

View file

@ -1329,3 +1329,41 @@ def test_non_org_admin_with_organizations_list():
organization_memberships=[membership],
)
assert _user_is_org_admin({"organizations": ["org-1"]}, user_obj) is False
def test_pass_through_subpath_auth_with_wildcard_in_openai_routes():
"""
Test that pass-through endpoints with include_subpath=true and auth=true
are accessible to non-admin users via wildcard route matching.
When auth=true and include_subpath=true, the wildcard path (e.g. /custom-endpoint/*)
should be added to openai_routes so that subpath requests like
/custom-endpoint/v1/infer are recognized as LLM API routes.
Regression test for: non-admin users getting 401 "Only proxy admin" error
on pass-through subpath requests.
"""
from litellm.proxy._types import LiteLLMRoutes
base_path = "/v1/ocr/nvidia/community/nemoretriever-ocr-v1"
wildcard_path = base_path + "/*"
# Simulate what init_pass_through_endpoints does when auth=true + include_subpath=true
original_routes = LiteLLMRoutes.openai_routes.value[:]
try:
LiteLLMRoutes.openai_routes.value.append(base_path)
LiteLLMRoutes.openai_routes.value.append(wildcard_path)
# Exact path should match
assert RouteChecks.is_llm_api_route(base_path) is True
# Subpath should match via wildcard
assert RouteChecks.is_llm_api_route(base_path + "/v1/infer") is True
# Deeper subpath should also match
assert RouteChecks.is_llm_api_route(base_path + "/v1/some/deep/path") is True
# Unrelated route should not match
assert RouteChecks.is_llm_api_route("/v1/some-other-endpoint") is False
finally:
LiteLLMRoutes.openai_routes.value[:] = original_routes