From 79b6cd29172ae2827259051b0b45b8af12c51a60 Mon Sep 17 00:00:00 2001 From: jesus Date: Thu, 17 Sep 2026 22:03:16 +0000 Subject: [PATCH] fix(auth): treat a missing org row as no org limits Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- litellm/proxy/auth/user_api_key_auth.py | 7 ++++--- tests/test_litellm/proxy/auth/test_user_api_key_auth.py | 5 +++-- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/litellm/proxy/auth/user_api_key_auth.py b/litellm/proxy/auth/user_api_key_auth.py index 89d543f9ccb..10924cf62bd 100644 --- a/litellm/proxy/auth/user_api_key_auth.py +++ b/litellm/proxy/auth/user_api_key_auth.py @@ -41,6 +41,7 @@ from litellm.litellm_core_utils.dot_notation_indexing import get_nested_value from litellm.proxy._types import * from litellm.proxy.auth.auth_checks import ( ExperimentalUIJWTToken, + OrganizationNotFoundError, TeamNotFoundError, _cache_key_object, _can_object_call_model, @@ -2634,13 +2635,13 @@ async def _inherit_org_identity( proxy_logging_obj=proxy_logging_obj, include_budget_table=True, ) - except Exception: # noqa: BLE001 # organization lookup must not fail authentication + except OrganizationNotFoundError: + return + except Exception: # noqa: BLE001 # DB outage handling is decided by allow_requests_on_db_unavailable if not PrismaDBExceptionHandler.should_allow_request_on_db_unavailable(): raise verbose_proxy_logger.debug("org lookup failed, continuing without org limits", exc_info=True) return - if org_object is None: - return user_api_key_auth_obj.organization_alias = org_object.organization_alias user_api_key_auth_obj.organization_metadata = org_object.metadata budget: Final = org_object.litellm_budget_table diff --git a/tests/test_litellm/proxy/auth/test_user_api_key_auth.py b/tests/test_litellm/proxy/auth/test_user_api_key_auth.py index 377e2d9342d..0bf49523869 100644 --- a/tests/test_litellm/proxy/auth/test_user_api_key_auth.py +++ b/tests/test_litellm/proxy/auth/test_user_api_key_auth.py @@ -35,6 +35,7 @@ from litellm.proxy._types import ( ) from litellm.proxy.auth.handle_jwt import JWTHandler from litellm.proxy.auth.auth_checks import ( + OrganizationNotFoundError, TeamNotFoundError, UserNotFoundError, get_key_object, @@ -5814,7 +5815,7 @@ async def test_centralized_common_checks_backfills_org_id_from_team(key_org_id, ("org-jwt", None, None, None, None, "success", False, False, "org-jwt", "acme-org", (12.5, 700, 7)), ("org-pinned", None, None, "preset", None, "success", False, False, "org-pinned", "preset", (None, None, None)), ("org-view", None, None, None, 3, "success", False, False, "org-view", None, (None, None, 3)), - ("org-missing", None, None, None, None, "missing", True, False, "org-missing", None, (None, None, None)), + ("org-missing", None, None, None, None, "missing", False, False, "org-missing", None, (None, None, None)), ("org-db-failure-allowed", None, None, None, None, "db_failure", True, False, "org-db-failure-allowed", None, (None, None, None)), ("org-db-failure-denied", None, None, None, None, "db_failure", False, True, "org-db-failure-denied", None, (None, None, None)), ("org-nobudget", None, None, None, None, "no_budget", False, False, "org-nobudget", "acme-org", (None, None, None)), @@ -5892,7 +5893,7 @@ async def test_centralized_common_checks_inherits_org_identity( ) as mock_checks, ): if lookup_mode == "missing": - mock_get_org_object.return_value = None + mock_get_org_object.side_effect = OrganizationNotFoundError("x") elif lookup_mode == "db_failure": mock_get_org_object.side_effect = RuntimeError("db unavailable")