mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-06 02:48:13 +00:00
style(proxy): black formatting for auth_v2 modules
This commit is contained in:
parent
de105b2d2d
commit
e0c5fca9fe
5 changed files with 16 additions and 19 deletions
|
|
@ -6,11 +6,9 @@ from fastapi import HTTPException, status
|
|||
|
||||
@runtime_checkable
|
||||
class Authenticator(Protocol):
|
||||
def can_handle(self, api_key: Optional[str]) -> bool:
|
||||
...
|
||||
def can_handle(self, api_key: Optional[str]) -> bool: ...
|
||||
|
||||
async def authenticate(self, api_key: str, ctx: "AuthContext") -> Any:
|
||||
...
|
||||
async def authenticate(self, api_key: str, ctx: "AuthContext") -> Any: ...
|
||||
|
||||
|
||||
class AuthContext:
|
||||
|
|
@ -122,9 +120,7 @@ class JWTAuthenticator:
|
|||
settings = _load_jwt_settings()
|
||||
key_set = await JWKSProvider(settings.jwks_uri).get_key_set()
|
||||
try:
|
||||
claims = verify(
|
||||
api_key, key_set, settings.issuer, settings.audience
|
||||
)
|
||||
claims = verify(api_key, key_set, settings.issuer, settings.audience)
|
||||
except JWTVerificationError as e:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
|
|
@ -218,9 +214,7 @@ class OAuth2IntrospectionAuthenticator:
|
|||
import httpx
|
||||
|
||||
auth = (
|
||||
(settings.client_id, settings.client_secret)
|
||||
if settings.client_id
|
||||
else None
|
||||
(settings.client_id, settings.client_secret) if settings.client_id else None
|
||||
)
|
||||
async with httpx.AsyncClient() as client:
|
||||
response = await client.post(
|
||||
|
|
|
|||
|
|
@ -74,9 +74,7 @@ async def user_api_key_auth_v2(
|
|||
try:
|
||||
authorize(principal, route, request_data, enforcer)
|
||||
except AuthorizationDenied as e:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_403_FORBIDDEN, detail=str(e)
|
||||
)
|
||||
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=str(e))
|
||||
|
||||
identity.request_route = route
|
||||
return identity
|
||||
|
|
|
|||
|
|
@ -34,9 +34,7 @@ def extract_identity(claims: Dict[str, Any], settings: JWTSettings) -> JWTIdenti
|
|||
"""
|
||||
user_id = claims.get(settings.user_id_claim)
|
||||
if not user_id:
|
||||
raise JWTClaimError(
|
||||
f"token missing user id claim '{settings.user_id_claim}'"
|
||||
)
|
||||
raise JWTClaimError(f"token missing user id claim '{settings.user_id_claim}'")
|
||||
|
||||
team_id = claims.get(settings.team_claim) if settings.team_claim else None
|
||||
|
||||
|
|
|
|||
|
|
@ -9,7 +9,9 @@ class JWTVerificationError(Exception):
|
|||
"""Raised when a token fails signature or standard-claim validation."""
|
||||
|
||||
|
||||
def build_claims_options(issuer: Optional[str], audience: Optional[str]) -> Dict[str, Any]:
|
||||
def build_claims_options(
|
||||
issuer: Optional[str], audience: Optional[str]
|
||||
) -> Dict[str, Any]:
|
||||
options: Dict[str, Any] = {"exp": {"essential": True}}
|
||||
if issuer:
|
||||
options["iss"] = {"essential": True, "value": issuer}
|
||||
|
|
|
|||
|
|
@ -35,8 +35,13 @@ def test_team_and_role_are_mapped():
|
|||
|
||||
def test_unmapped_role_value_yields_no_role():
|
||||
# An arbitrary IdP role string must not be trusted as a litellm role.
|
||||
settings = JWTSettings(jwks_uri="x", role_claim="role", role_map={"a": "proxy_admin"})
|
||||
assert extract_identity({"sub": "u1", "role": "totally-unknown"}, settings).role is None
|
||||
settings = JWTSettings(
|
||||
jwks_uri="x", role_claim="role", role_map={"a": "proxy_admin"}
|
||||
)
|
||||
assert (
|
||||
extract_identity({"sub": "u1", "role": "totally-unknown"}, settings).role
|
||||
is None
|
||||
)
|
||||
|
||||
|
||||
def test_missing_user_id_raises():
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue