From d450935a9d804f67b8e8f9b2d4fb6b51cf2eea74 Mon Sep 17 00:00:00 2001 From: Yassin Kortam Date: Mon, 8 Jun 2026 14:27:44 -0700 Subject: [PATCH] fix(identity): preserve empty access_group_ids list across adapter roundtrip --- litellm/identity/adapter.py | 2 +- tests/test_litellm/identity/test_adapter.py | 9 +++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/litellm/identity/adapter.py b/litellm/identity/adapter.py index 478c7f9a77a..2b8ee777c8d 100644 --- a/litellm/identity/adapter.py +++ b/litellm/identity/adapter.py @@ -104,7 +104,7 @@ def identity_context_to_user_api_key_auth( kwargs: dict = { "end_user_id": ctx.end_user_id, "access_group_ids": ( - list(ctx.access_group_ids) if ctx.access_group_ids else None + list(ctx.access_group_ids) if ctx.access_group_ids is not None else None ), } diff --git a/tests/test_litellm/identity/test_adapter.py b/tests/test_litellm/identity/test_adapter.py index 9f8d2d8ee6a..fd5c5dbf4d9 100644 --- a/tests/test_litellm/identity/test_adapter.py +++ b/tests/test_litellm/identity/test_adapter.py @@ -57,6 +57,15 @@ def test_roundtrip_preserves_api_key_identity_fields(): assert back.token == uak.token +def test_access_group_ids_empty_list_survives_roundtrip(): + uak = UserAPIKeyAuth(api_key="sk-x", user_id="u", access_group_ids=[]) + ctx = user_api_key_auth_to_identity_context(uak) + assert ctx.access_group_ids == [] + + back = identity_context_to_user_api_key_auth(ctx) + assert back.access_group_ids == [] + + def test_token_hash_not_double_hashed(): ctx = IdentityContext(principal=ApiKeyPrincipal(token_hash="abc123")) back = identity_context_to_user_api_key_auth(ctx)