From b2e3d6ed2b1bb504fe6963a1adbe0ad67fe1b554 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 6 May 2026 23:38:27 +0000 Subject: [PATCH] fix: include team admins in project access check The get_project endpoint's team-membership check only iterated team.members_with_roles, so users present in team.admins but not members_with_roles were denied access. Restore the admin check to match _check_user_permission_for_project. --- .../management_endpoints/project_endpoints.py | 21 +++++++++++-------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/enterprise/litellm_enterprise/proxy/management_endpoints/project_endpoints.py b/enterprise/litellm_enterprise/proxy/management_endpoints/project_endpoints.py index 75229bacc8f..bc8ceeb45bc 100644 --- a/enterprise/litellm_enterprise/proxy/management_endpoints/project_endpoints.py +++ b/enterprise/litellm_enterprise/proxy/management_endpoints/project_endpoints.py @@ -877,15 +877,18 @@ async def project_info( ) if team: caller_user_id = user_api_key_dict.user_id - for m in team.members_with_roles or []: - m_user_id = ( - m.get("user_id") - if isinstance(m, dict) - else getattr(m, "user_id", None) - ) - if m_user_id == caller_user_id: - is_team_member = True - break + if team.admins and caller_user_id in team.admins: + is_team_member = True + else: + for m in team.members_with_roles or []: + m_user_id = ( + m.get("user_id") + if isinstance(m, dict) + else getattr(m, "user_id", None) + ) + if m_user_id == caller_user_id: + is_team_member = True + break if not (is_admin or is_team_member): raise HTTPException(