diff --git a/.gitignore b/.gitignore index 572830d35f6..13cc075ac2e 100644 --- a/.gitignore +++ b/.gitignore @@ -3,6 +3,7 @@ .venv_policy_test .env .claude +.claude-team-notes/ .newenv newenv/* litellm/proxy/myenv/* diff --git a/litellm/identity/__init__.py b/litellm/identity/__init__.py index 59a02e1e15f..ed1c30abbee 100644 --- a/litellm/identity/__init__.py +++ b/litellm/identity/__init__.py @@ -1,13 +1,13 @@ """Caller-identity module. -Phase 1: domain types + extractors + bidirectional adapter to +Domain types, the identity cache/store, and a bidirectional adapter to ``UserAPIKeyAuth``. The proxy still drives identity through ``litellm/proxy/auth/`` today; this module is the new home those flows -will migrate to. +migrate to. The public surface is small on purpose; downstream code should depend on ``IdentityContext`` and the ``Principal`` union, not on individual -extractor internals. +internals. """ from litellm.identity.cache import IdentityCache diff --git a/litellm/identity/adapter.py b/litellm/identity/adapter.py index 5185eea6973..efd0f3c867e 100644 --- a/litellm/identity/adapter.py +++ b/litellm/identity/adapter.py @@ -1,8 +1,8 @@ """Bidirectional bridge between ``IdentityContext`` and ``UserAPIKeyAuth``. -Phase 1 keeps the legacy Pydantic model as the universal carrier. These -two pure functions let new code work in terms of ``IdentityContext`` -without forcing call sites to migrate today. +The legacy Pydantic model stays the universal carrier. These two pure +functions let new code work in terms of ``IdentityContext`` without +forcing call sites to migrate today. Invariants: - ``identity_context_to_user_api_key_auth(uak.to_identity_context())`` diff --git a/litellm/identity/context.py b/litellm/identity/context.py index 386c3e051b8..f3637f9a9cb 100644 --- a/litellm/identity/context.py +++ b/litellm/identity/context.py @@ -1,9 +1,9 @@ """The per-request identity bundle. ``IdentityContext`` is what downstream consumers (auth, spend, guardrails, -logging, audit) should read identity from once Phase 2 migration is done. -In Phase 1 it travels alongside the legacy ``UserAPIKeyAuth`` via the -adapter functions in ``litellm.identity.adapter``. +logging, audit) should read identity from. Today it travels alongside the +legacy ``UserAPIKeyAuth`` via the adapter functions in +``litellm.identity.adapter``. The bundle is mutable on purpose: identity fields like ``end_user_id`` are sometimes resolved or overridden after initial extraction, and the diff --git a/litellm/identity/invalidation.py b/litellm/identity/invalidation.py index e470cef054c..ba2dac79f93 100644 --- a/litellm/identity/invalidation.py +++ b/litellm/identity/invalidation.py @@ -12,9 +12,9 @@ Two flavors: a mismatch as a miss. The legacy ``_delete_cache_key_object`` and the per-table cache deletes -in ``auth_checks.py`` are left in place by Phase 2. These hooks run -side-by-side so we don't strand a partially-deployed fleet that's still -reading from the legacy cache keys. +in ``auth_checks.py`` stay in place. These hooks run side-by-side so we +don't strand a partially-deployed fleet that's still reading from the +legacy cache keys. """ from __future__ import annotations diff --git a/litellm/identity/principal.py b/litellm/identity/principal.py index 41c69c09877..58c264ebe5b 100644 --- a/litellm/identity/principal.py +++ b/litellm/identity/principal.py @@ -3,7 +3,7 @@ A ``Principal`` answers "who is making this request" using only the fields that uniquely identify the caller. Per-row enrichment (budgets, team rows, object permissions) is intentionally not modeled here; that data continues -to ride on ``UserAPIKeyAuth`` in Phase 1. +to ride on ``UserAPIKeyAuth``. Each subtype is a frozen dataclass with a ``kind`` discriminator suitable for ``match``-style dispatch.