docs(identity): drop Phase 1/2 framing from module docstrings

This commit is contained in:
Yassin Kortam 2026-06-08 14:20:35 -07:00
parent 043d2d65b1
commit bf33cc24e3
6 changed files with 14 additions and 13 deletions

1
.gitignore vendored
View file

@ -3,6 +3,7 @@
.venv_policy_test
.env
.claude
.claude-team-notes/
.newenv
newenv/*
litellm/proxy/myenv/*

View file

@ -1,13 +1,13 @@
"""Caller-identity module.
Phase 1: domain types + extractors + bidirectional adapter to
Domain types, the identity cache/store, and a bidirectional adapter to
``UserAPIKeyAuth``. The proxy still drives identity through
``litellm/proxy/auth/`` today; this module is the new home those flows
will migrate to.
migrate to.
The public surface is small on purpose; downstream code should depend on
``IdentityContext`` and the ``Principal`` union, not on individual
extractor internals.
internals.
"""
from litellm.identity.cache import IdentityCache

View file

@ -1,8 +1,8 @@
"""Bidirectional bridge between ``IdentityContext`` and ``UserAPIKeyAuth``.
Phase 1 keeps the legacy Pydantic model as the universal carrier. These
two pure functions let new code work in terms of ``IdentityContext``
without forcing call sites to migrate today.
The legacy Pydantic model stays the universal carrier. These two pure
functions let new code work in terms of ``IdentityContext`` without
forcing call sites to migrate today.
Invariants:
- ``identity_context_to_user_api_key_auth(uak.to_identity_context())``

View file

@ -1,9 +1,9 @@
"""The per-request identity bundle.
``IdentityContext`` is what downstream consumers (auth, spend, guardrails,
logging, audit) should read identity from once Phase 2 migration is done.
In Phase 1 it travels alongside the legacy ``UserAPIKeyAuth`` via the
adapter functions in ``litellm.identity.adapter``.
logging, audit) should read identity from. Today it travels alongside the
legacy ``UserAPIKeyAuth`` via the adapter functions in
``litellm.identity.adapter``.
The bundle is mutable on purpose: identity fields like ``end_user_id`` are
sometimes resolved or overridden after initial extraction, and the

View file

@ -12,9 +12,9 @@ Two flavors:
a mismatch as a miss.
The legacy ``_delete_cache_key_object`` and the per-table cache deletes
in ``auth_checks.py`` are left in place by Phase 2. These hooks run
side-by-side so we don't strand a partially-deployed fleet that's still
reading from the legacy cache keys.
in ``auth_checks.py`` stay in place. These hooks run side-by-side so we
don't strand a partially-deployed fleet that's still reading from the
legacy cache keys.
"""
from __future__ import annotations

View file

@ -3,7 +3,7 @@
A ``Principal`` answers "who is making this request" using only the fields
that uniquely identify the caller. Per-row enrichment (budgets, team rows,
object permissions) is intentionally not modeled here; that data continues
to ride on ``UserAPIKeyAuth`` in Phase 1.
to ride on ``UserAPIKeyAuth``.
Each subtype is a frozen dataclass with a ``kind`` discriminator suitable
for ``match``-style dispatch.