diff --git a/litellm/proxy/auth/custom_rbac.py b/litellm/proxy/auth/custom_rbac.py index b48e9f854d5..0c22000ef6f 100644 --- a/litellm/proxy/auth/custom_rbac.py +++ b/litellm/proxy/auth/custom_rbac.py @@ -195,8 +195,8 @@ async def get_active_custom_rbac_engine() -> CustomRBACEngine | None: if cached is not None: return cached - table: Final = _custom_role_table() try: + table: Final = _custom_role_table() db_roles: Final = () if table is None else await get_db_custom_rbac_roles(table=table) except Exception as exc: # noqa: BLE001 # any DB failure must keep the last known policy, not drop it verbose_proxy_logger.exception("Failed to load custom RBAC roles from the DB: %s", exc) diff --git a/tests/test_litellm/proxy/auth/test_custom_rbac.py b/tests/test_litellm/proxy/auth/test_custom_rbac.py index 275200b194f..571856e0bb3 100644 --- a/tests/test_litellm/proxy/auth/test_custom_rbac.py +++ b/tests/test_litellm/proxy/auth/test_custom_rbac.py @@ -250,6 +250,17 @@ class TestEngineLoading: ): assert await get_active_custom_rbac_engine() is None + @pytest.mark.asyncio + async def test_prisma_client_without_db_does_not_break_auth(self): + class _ClientWithoutDb: + pass + + with ( + patch("litellm.proxy.proxy_server.general_settings", {}), + patch("litellm.proxy.proxy_server.prisma_client", _ClientWithoutDb()), + ): + assert await get_active_custom_rbac_engine() is None + @pytest.mark.asyncio async def test_assigning_undefined_custom_role_is_rejected(self): table = _FakeTable(records=(_FakeRecord("db-role", ("/team/info",)),))