Merge pull request #23666 from BerriAI/litellm_fix-default-user-perms-not-synced-with-ui

fix: align DefaultInternalUserParams Pydantic default with runtime fallback
This commit is contained in:
ryan-crabbe 2026-03-16 11:58:30 -07:00 • committed by GitHub
commit 4f2fe3378f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 32 additions and 1 deletions

View file

@ -4262,7 +4262,7 @@ class DefaultInternalUserParams(LiteLLMPydanticObjectBase):
LitellmUserRoles.PROXY_ADMIN_VIEW_ONLY,
]
] = Field(
default=LitellmUserRoles.INTERNAL_USER,
default=LitellmUserRoles.INTERNAL_USER_VIEW_ONLY,
description="Default role assigned to new users created",
)
max_budget: Optional[float] = Field(

View file

@ -111,6 +111,37 @@ class TestProxySettingEndpoints:
assert "user_role" in data["field_schema"]["properties"]
assert "description" in data["field_schema"]["properties"]["user_role"]
def test_get_internal_user_settings_fresh_db_defaults_to_viewer(
self, mock_auth, monkeypatch
):
"""
On a fresh DB with no saved settings, the GET endpoint should return
INTERNAL_USER_VIEW_ONLY as the default role — matching the runtime
fallback in SSO/SCIM/JWT provisioning paths.
"""
# Simulate fresh DB: no default_internal_user_params in config
empty_config = {
"litellm_settings": {},
"general_settings": {},
"environment_variables": {},
}
from litellm.proxy.proxy_server import proxy_config
async def mock_get_config():
return empty_config
monkeypatch.setattr(proxy_config, "get_config", mock_get_config)
response = client.get("/get/internal_user_settings")
assert response.status_code == 200
values = response.json()["values"]
assert values["user_role"] == LitellmUserRoles.INTERNAL_USER_VIEW_ONLY, (
f"Fresh DB should default to INTERNAL_USER_VIEW_ONLY, got {values['user_role']}. "
"The Pydantic default must match the runtime fallback."
)
def test_update_internal_user_settings(
self, mock_proxy_config, mock_auth, monkeypatch
):