mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-08 03:08:45 +00:00
fix: Add PROXY_ADMIN role to system user for key rotation (#21896)
* fix: Add PROXY_ADMIN role to system user for key rotation The key rotation worker was failing with 'You are not authorized to regenerate this key' when rotating team keys. This was because the system user created by get_litellm_internal_jobs_user_api_key_auth() was missing the user_role field. Without user_role=PROXY_ADMIN, the system user couldn't bypass team permission checks in can_team_member_execute_key_management_endpoint(), causing authorization failures for team key rotation. This fix adds user_role=LitellmUserRoles.PROXY_ADMIN to the system user, allowing it to bypass team permission checks and successfully rotate keys for all teams. * test: Add unit test for system user PROXY_ADMIN role - Verify internal jobs system user has PROXY_ADMIN role - Critical for key rotation to bypass team permission checks - Regression test for PR #21896
This commit is contained in:
parent
8b50703f74
commit
594600dcb5
2 changed files with 25 additions and 0 deletions
|
|
@ -2417,6 +2417,7 @@ class UserAPIKeyAuth(
|
|||
key_alias=LITELLM_INTERNAL_JOBS_SERVICE_ACCOUNT_NAME,
|
||||
team_alias="system",
|
||||
user_id="system",
|
||||
user_role=LitellmUserRoles.PROXY_ADMIN,
|
||||
)
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -45,3 +45,27 @@ def test_audit_log_masking():
|
|||
json_before_value = json.loads(audit_log.before_value)
|
||||
assert json_before_value["token"] == "1q2132r222"
|
||||
assert json_before_value["key"] == "sk-1*****7890"
|
||||
|
||||
|
||||
def test_internal_jobs_user_has_proxy_admin_role():
|
||||
"""
|
||||
Test that the internal jobs system user has PROXY_ADMIN role.
|
||||
|
||||
This is critical for key rotation to work properly. The system user needs
|
||||
PROXY_ADMIN role to bypass team permission checks in
|
||||
TeamMemberPermissionChecks.can_team_member_execute_key_management_endpoint()
|
||||
|
||||
Regression test for: https://github.com/BerriAI/litellm/pull/21896
|
||||
"""
|
||||
from litellm.proxy._types import LitellmUserRoles, UserAPIKeyAuth
|
||||
|
||||
# Get the system user used for internal jobs like key rotation
|
||||
system_user = UserAPIKeyAuth.get_litellm_internal_jobs_user_api_key_auth()
|
||||
|
||||
# Verify the system user has PROXY_ADMIN role
|
||||
assert system_user.user_role == LitellmUserRoles.PROXY_ADMIN
|
||||
|
||||
# Verify other expected properties
|
||||
assert system_user.user_id == "system"
|
||||
assert system_user.team_id == "system"
|
||||
assert system_user.team_alias == "system"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue