address greptile review feedback (greploop iteration 4)

- Move extra_permissions validation before budget upsert to prevent
  partial DB writes on validation failure

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
yuneng-jiang 2026-03-20 22:54:25 -07:00
parent 7c9664147f
commit b78e3bad85

View file

@ -2421,20 +2421,7 @@ async def team_member_update(
identified_budget_id = tm.budget_id
break
### upsert new budget
async with prisma_client.db.tx() as tx:
await _upsert_budget_and_membership(
tx=tx,
team_id=data.team_id,
user_id=received_user_id,
max_budget=data.max_budget_in_team,
existing_budget_id=identified_budget_id,
user_api_key_dict=user_api_key_dict,
tpm_limit=data.tpm_limit,
rpm_limit=data.rpm_limit,
)
### Validate extra_permissions before applying any changes
### Validate extra_permissions BEFORE any DB writes
if data.extra_permissions is not None:
from litellm.proxy.auth.permissions import VALID_PERMISSIONS
@ -2448,6 +2435,19 @@ async def team_member_update(
},
)
### upsert new budget
async with prisma_client.db.tx() as tx:
await _upsert_budget_and_membership(
tx=tx,
team_id=data.team_id,
user_id=received_user_id,
max_budget=data.max_budget_in_team,
existing_budget_id=identified_budget_id,
user_api_key_dict=user_api_key_dict,
tpm_limit=data.tpm_limit,
rpm_limit=data.rpm_limit,
)
### Apply role and extra_permissions updates in-memory, then do a single DB write
members_changed = data.role is not None or data.extra_permissions is not None
if members_changed: