fix(rbac): keep auth working when the prisma client exposes no db

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
mateo 2026-08-21 03:46:57 +00:00
parent 858a80d3aa
commit b7f594d868
2 changed files with 12 additions and 1 deletions

View file

@ -195,8 +195,8 @@ async def get_active_custom_rbac_engine() -> CustomRBACEngine | None:
if cached is not None:
return cached
table: Final = _custom_role_table()
try:
table: Final = _custom_role_table()
db_roles: Final = () if table is None else await get_db_custom_rbac_roles(table=table)
except Exception as exc: # noqa: BLE001 # any DB failure must keep the last known policy, not drop it
verbose_proxy_logger.exception("Failed to load custom RBAC roles from the DB: %s", exc)

View file

@ -250,6 +250,17 @@ class TestEngineLoading:
):
assert await get_active_custom_rbac_engine() is None
@pytest.mark.asyncio
async def test_prisma_client_without_db_does_not_break_auth(self):
class _ClientWithoutDb:
pass
with (
patch("litellm.proxy.proxy_server.general_settings", {}),
patch("litellm.proxy.proxy_server.prisma_client", _ClientWithoutDb()),
):
assert await get_active_custom_rbac_engine() is None
@pytest.mark.asyncio
async def test_assigning_undefined_custom_role_is_rejected(self):
table = _FakeTable(records=(_FakeRecord("db-role", ("/team/info",)),))