fix: Add PROXY_ADMIN role to system user for key rotation (#21896)

* fix: Add PROXY_ADMIN role to system user for key rotation

The key rotation worker was failing with 'You are not authorized to regenerate this key'
when rotating team keys. This was because the system user created by
get_litellm_internal_jobs_user_api_key_auth() was missing the user_role field.

Without user_role=PROXY_ADMIN, the system user couldn't bypass team permission checks
in can_team_member_execute_key_management_endpoint(), causing authorization failures
for team key rotation.

This fix adds user_role=LitellmUserRoles.PROXY_ADMIN to the system user, allowing
it to bypass team permission checks and successfully rotate keys for all teams.

* test: Add unit test for system user PROXY_ADMIN role

- Verify internal jobs system user has PROXY_ADMIN role
- Critical for key rotation to bypass team permission checks
- Regression test for PR #21896
This commit is contained in:
milan-berri 2026-02-28 05:11:29 +02:00 • committed by GitHub
parent 8b50703f74
commit 594600dcb5
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 25 additions and 0 deletions

View file

@ -2417,6 +2417,7 @@ class UserAPIKeyAuth(
key_alias=LITELLM_INTERNAL_JOBS_SERVICE_ACCOUNT_NAME,
team_alias="system",
user_id="system",
user_role=LitellmUserRoles.PROXY_ADMIN,
)

View file

@ -45,3 +45,27 @@ def test_audit_log_masking():
json_before_value = json.loads(audit_log.before_value)
assert json_before_value["token"] == "1q2132r222"
assert json_before_value["key"] == "sk-1*****7890"
def test_internal_jobs_user_has_proxy_admin_role():
"""
Test that the internal jobs system user has PROXY_ADMIN role.
This is critical for key rotation to work properly. The system user needs
PROXY_ADMIN role to bypass team permission checks in
TeamMemberPermissionChecks.can_team_member_execute_key_management_endpoint()
Regression test for: https://github.com/BerriAI/litellm/pull/21896
"""
from litellm.proxy._types import LitellmUserRoles, UserAPIKeyAuth
# Get the system user used for internal jobs like key rotation
system_user = UserAPIKeyAuth.get_litellm_internal_jobs_user_api_key_auth()
# Verify the system user has PROXY_ADMIN role
assert system_user.user_role == LitellmUserRoles.PROXY_ADMIN
# Verify other expected properties
assert system_user.user_id == "system"
assert system_user.team_id == "system"
assert system_user.team_alias == "system"