[Fix] Sync UI settings into general_settings on proxy startup

After a server restart, RBAC flags (disable_agents_for_internal_users, etc.)
were only loaded into general_settings lazily when get_ui_settings or
update_ui_settings was called. This meant restrictions were silently bypassed
until someone hit one of those endpoints.

Add _sync_ui_settings_to_general_settings() to ProxyStartupEvent that reads
the litellm_uisettings DB record and syncs _RUNTIME_GENERAL_SETTINGS_FLAGS
into general_settings immediately after prisma_client is initialized.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
yuneng-jiang 2026-03-05 16:29:13 -08:00
parent 05d2ccdf56
commit d904b92f5a

View file

@ -885,6 +885,9 @@ async def proxy_startup_event(app: FastAPI): # noqa: PLR0915
await ProxyStartupEvent._update_default_team_member_budget()
## SYNC UI SETTINGS ##
await ProxyStartupEvent._sync_ui_settings_to_general_settings()
# Start background health checks AFTER models are loaded and index is built
if use_background_health_checks:
asyncio.create_task(
@ -5639,6 +5642,41 @@ class ProxyStartupEvent:
teams=teams_pydantic_obj, user_api_key_dict=UserAPIKeyAuth(token=hash_token(master_key)) # type: ignore
)
@classmethod
async def _sync_ui_settings_to_general_settings(cls):
"""
Load persisted UI settings from the database and sync runtime flags
into general_settings so they take effect immediately after startup.
"""
try:
import json
from litellm.proxy.ui_crud_endpoints.proxy_setting_endpoints import (
_RUNTIME_GENERAL_SETTINGS_FLAGS,
)
db_record = await prisma_client.db.litellm_uisettings.find_unique(
where={"id": "ui_settings"}
)
if db_record and db_record.ui_settings:
raw = db_record.ui_settings
ui_settings = json.loads(raw) if isinstance(raw, str) else dict(raw)
flags_to_sync = {
k: ui_settings[k]
for k in _RUNTIME_GENERAL_SETTINGS_FLAGS
if k in ui_settings
}
if flags_to_sync:
general_settings.update(flags_to_sync)
verbose_proxy_logger.info(
"Synced UI settings to general_settings on startup: %s",
list(flags_to_sync.keys()),
)
except Exception as e:
verbose_proxy_logger.debug(
"UI settings sync on startup skipped or failed: %s", e
)
@classmethod
async def initialize_scheduled_background_jobs( # noqa: PLR0915
cls,