From de8a52f294e45bdd0d8f18b12e9b8d9be0137b48 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 24 Apr 2026 19:51:53 -0700 Subject: [PATCH] fix: allow internal_user to access /project/list and /project/info Add /project/list and /project/info to self_managed_routes and admin_viewer_routes in LiteLLMRoutes so non-admin users can reach these endpoints. The endpoints already enforce team-membership access control internally (non-admins see only projects from their teams), but RouteChecks.non_proxy_admin_allowed_routes_check() was rejecting the request with 401 before the endpoint logic ran. --- litellm/proxy/_types.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/litellm/proxy/_types.py b/litellm/proxy/_types.py index f11b29103be..7b71cf37943 100644 --- a/litellm/proxy/_types.py +++ b/litellm/proxy/_types.py @@ -681,6 +681,9 @@ class LiteLLMRoutes(enum.Enum): # Team guardrail submissions - endpoint scopes results to caller's teams (non-admin) "/guardrails/submissions", "/guardrails/submissions/{guardrail_id}", + # Project routes - endpoints scope results to caller's teams (non-admin gets only their projects) + "/project/list", + "/project/info", ] # routes that manage their own allowed/disallowed logic ## Org Admin Routes ## @@ -714,6 +717,8 @@ class LiteLLMRoutes(enum.Enum): "/global/activity", "/global/activity/model", "/global/activity/cache_hits", + "/project/list", + "/project/info", ] + info_routes # All routes accesible by an Org Admin