mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
fix(proxy): allow non-admin users to access pass-through subpath routes with auth
When a pass-through endpoint has both auth=true and include_subpath=true, non-admin users got 401 errors on subpath requests because only the base path was registered in openai_routes. Now the wildcard path is also registered so the auth check recognizes subpath requests as LLM API routes. Also fixes pre-existing pyright error where logging_obj was possibly unbound in the except block.
This commit is contained in:
parent
0ecced9780
commit
4829de6102
2 changed files with 45 additions and 0 deletions
|
|
@ -651,6 +651,7 @@ async def pass_through_request( # noqa: PLR0915
|
|||
_parsed_body: Optional[dict] = None
|
||||
# kwargs for pass through endpoint, contains metadata, litellm_params, call_type, litellm_call_id, passthrough_logging_payload
|
||||
kwargs: Optional[dict] = None
|
||||
logging_obj: Optional[Logging] = None
|
||||
|
||||
#########################################################
|
||||
try:
|
||||
|
|
@ -2262,6 +2263,12 @@ async def initialize_pass_through_endpoints(
|
|||
|
||||
# Add wildcard route for sub-paths
|
||||
if endpoint.get("include_subpath", False) is True:
|
||||
# Register wildcard path in openai_routes so non-admin users
|
||||
# can access subpath routes when auth is enabled
|
||||
if _auth is not None and str(_auth).lower() == "true":
|
||||
_wildcard_path = _path.rstrip("/") + "/*"
|
||||
if _wildcard_path not in LiteLLMRoutes.openai_routes.value:
|
||||
LiteLLMRoutes.openai_routes.value.append(_wildcard_path)
|
||||
InitPassThroughEndpointHelpers.add_subpath_route(
|
||||
app=app,
|
||||
path=_path,
|
||||
|
|
|
|||
|
|
@ -1329,3 +1329,41 @@ def test_non_org_admin_with_organizations_list():
|
|||
organization_memberships=[membership],
|
||||
)
|
||||
assert _user_is_org_admin({"organizations": ["org-1"]}, user_obj) is False
|
||||
|
||||
|
||||
def test_pass_through_subpath_auth_with_wildcard_in_openai_routes():
|
||||
"""
|
||||
Test that pass-through endpoints with include_subpath=true and auth=true
|
||||
are accessible to non-admin users via wildcard route matching.
|
||||
|
||||
When auth=true and include_subpath=true, the wildcard path (e.g. /custom-endpoint/*)
|
||||
should be added to openai_routes so that subpath requests like
|
||||
/custom-endpoint/v1/infer are recognized as LLM API routes.
|
||||
|
||||
Regression test for: non-admin users getting 401 "Only proxy admin" error
|
||||
on pass-through subpath requests.
|
||||
"""
|
||||
from litellm.proxy._types import LiteLLMRoutes
|
||||
|
||||
base_path = "/v1/ocr/nvidia/community/nemoretriever-ocr-v1"
|
||||
wildcard_path = base_path + "/*"
|
||||
|
||||
# Simulate what init_pass_through_endpoints does when auth=true + include_subpath=true
|
||||
original_routes = LiteLLMRoutes.openai_routes.value[:]
|
||||
try:
|
||||
LiteLLMRoutes.openai_routes.value.append(base_path)
|
||||
LiteLLMRoutes.openai_routes.value.append(wildcard_path)
|
||||
|
||||
# Exact path should match
|
||||
assert RouteChecks.is_llm_api_route(base_path) is True
|
||||
|
||||
# Subpath should match via wildcard
|
||||
assert RouteChecks.is_llm_api_route(base_path + "/v1/infer") is True
|
||||
|
||||
# Deeper subpath should also match
|
||||
assert RouteChecks.is_llm_api_route(base_path + "/v1/some/deep/path") is True
|
||||
|
||||
# Unrelated route should not match
|
||||
assert RouteChecks.is_llm_api_route("/v1/some-other-endpoint") is False
|
||||
finally:
|
||||
LiteLLMRoutes.openai_routes.value[:] = original_routes
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue