From a443a68347695f51e7b0509683981bfa9286f321 Mon Sep 17 00:00:00 2001 From: jesus Date: Wed, 9 Sep 2026 00:04:31 +0000 Subject: [PATCH] refactor(auth): sync session token team grants from resolved team object Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- litellm/proxy/auth/user_api_key_auth.py | 39 ++----------------------- 1 file changed, 3 insertions(+), 36 deletions(-) diff --git a/litellm/proxy/auth/user_api_key_auth.py b/litellm/proxy/auth/user_api_key_auth.py index b7b7c8d7f1c..45a32379054 100644 --- a/litellm/proxy/auth/user_api_key_auth.py +++ b/litellm/proxy/auth/user_api_key_auth.py @@ -1742,15 +1742,6 @@ async def _user_api_key_auth_builder( ): valid_token = ExperimentalUIJWTToken.get_key_object_from_ui_hash_key(api_key) - if valid_token is not None and valid_token.is_session_token: - valid_token = await _refresh_session_token_team_grants( - valid_token=valid_token, - prisma_client=prisma_client, - user_api_key_cache=user_api_key_cache, - parent_otel_span=parent_otel_span, - proxy_logging_obj=proxy_logging_obj, - ) - if ( valid_token is not None and isinstance(valid_token, UserAPIKeyAuth) @@ -2214,6 +2205,9 @@ async def _user_api_key_auth_builder( # guardrails (or any other metadata) added after the key was cached # are picked up on subsequent requests without a cache eviction. valid_token.team_metadata = _team_obj.metadata + if valid_token.is_session_token: + valid_token.team_models = list(_team_obj.models) # mutable-ok: auth model requires a fresh list + valid_token.team_alias = _team_obj.team_alias else: valid_token.team_object_permission = None @@ -2353,33 +2347,6 @@ def _team_obj_from_token(valid_token: UserAPIKeyAuth) -> LiteLLM_TeamTableCached ) -async def _refresh_session_token_team_grants( - valid_token: UserAPIKeyAuth, - prisma_client: PrismaClient | None, - user_api_key_cache: UserApiKeyCache, - parent_otel_span: Span | None, - proxy_logging_obj: ProxyLogging, -) -> UserAPIKeyAuth: - if valid_token.team_id is None or valid_token.team_id == UI_TEAM_ID or prisma_client is None: - return valid_token - try: - team_obj: Final = await get_team_object( - team_id=valid_token.team_id, - prisma_client=prisma_client, - user_api_key_cache=user_api_key_cache, - parent_otel_span=parent_otel_span, - proxy_logging_obj=proxy_logging_obj, - ) - except HTTPException: - return valid_token - return valid_token.model_copy( - update={ # mutable-ok: model_copy requires a mutable update mapping - "team_models": list(team_obj.models), # mutable-ok: auth model requires a fresh list - "team_alias": team_obj.team_alias, - } - ) - - def _token_can_vouch_for_team(valid_token: UserAPIKeyAuth, lookup_error: BaseException) -> bool: """Whether the token's own team fields may stand in for a team that failed to resolve, without widening access.