mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
fix(team): mypy — guard organization_id None before _verify_org_access call
``LiteLLM_OrganizationTableUpdate.organization_id`` is typed ``Optional[str]`` to allow update payloads that don't change the id. ``_verify_org_access`` expects ``str``. Add an explicit None check that raises 400 before the access guard fires — previously this would have crashed at runtime on a malformed update payload. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
a9bc5549b2
commit
6c386af9c7
1 changed files with 6 additions and 0 deletions
|
|
@ -500,6 +500,12 @@ async def update_organization(
|
|||
if data.updated_by is None:
|
||||
data.updated_by = user_api_key_dict.user_id
|
||||
|
||||
if data.organization_id is None:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail={"error": "organization_id is required"},
|
||||
)
|
||||
|
||||
# IDOR guard: only proxy admins / org admins of THIS org may update
|
||||
# it. Without this, any authenticated key holder could rewrite
|
||||
# another organization's metadata, budgets, and object permissions.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue