fix(otel/v2): drop dead team lookups flagged in review

The /key/update path fetched the key's team into _key_team only to feed the
team-admin/org-admin assignment flags removed in the admin-only refactor; it is
now unused, so drop the wasted DB round-trip. The resolver's org lookup passed
check_db_only=True, forcing a synchronous DB query on every team-key request even
though the team is already resident in the cache from auth; drop it so the lookup
is cache-first. Also correct two comments that still claimed team or org admins
may assign logging_exporters.
This commit is contained in:
Yucheng Zhu 2026-07-28 10:06:47 -07:00
parent 04e4effba3
commit e5760dc265
2 changed files with 7 additions and 26 deletions

View file

@ -614,7 +614,6 @@ async def _effective_org_id(user_api_key_dict: UserAPIKeyAuth) -> str | None:
prisma_client=proxy_server.prisma_client,
user_api_key_cache=proxy_server.user_api_key_cache,
parent_otel_span=getattr(user_api_key_dict, "parent_otel_span", None),
check_db_only=True,
)
except HTTPException:
return None

View file

@ -1648,10 +1648,8 @@ async def generate_key_fn(
route=KeyManagementRoutes.KEY_GENERATE,
)
# Team-admin of the key's team or org-admin of that team's org may assign
# logging_exporters on team-owned keys. Personal keys (no team_table) stay
# proxy-admin only. Skip the role lookup when the field isn't in the payload
# to keep /key/generate cheap for the common case.
# logging_exporters on a key is proxy-admin only. Skip the check when the
# field isn't in the payload to keep /key/generate cheap for the common case.
if data.logging_exporters is not None:
validate_logging_exporter_field(data.logging_exporters, user_api_key_dict)
@ -1832,10 +1830,8 @@ async def generate_service_account_key_fn(
route=KeyManagementRoutes.KEY_GENERATE_SERVICE_ACCOUNT,
)
# Same logging_exporters gate as /key/generate. Without this, a caller
# eligible for service-account creation could set metadata.logging_exporters
# and route future traces to a destination they aren't allowed to assign
# (Veria F3). Skip the lookup unless the field is being written.
# Same logging_exporters gate as /key/generate: proxy-admin only. Skip the
# check unless the field is being written.
from litellm.proxy.management_endpoints.logging_exporter_validation import (
validate_logging_exporter_field,
)
@ -2627,24 +2623,10 @@ async def update_key_fn( # noqa: C901 # single endpoint handling many optional
prisma_client=prisma_client,
)
# logging-exporters validation runs once the key's team is known so a
# team-admin or org-admin of that team can attach destinations. The
# validator no-ops when the effective value doesn't change; pass the
# stored column value so a non-admin cannot clear an admin-assigned one.
# logging_exporters is proxy-admin only. The validator no-ops when the
# effective value doesn't change; pass the stored column value so a
# non-admin cannot clear an admin-assigned one.
if data.logging_exporters is not None:
_key_team_id = getattr(existing_key_row, "team_id", None)
_key_team = None
if _key_team_id is not None:
try:
_key_team = await get_team_object(
team_id=_key_team_id,
prisma_client=prisma_client,
user_api_key_cache=user_api_key_cache,
parent_otel_span=user_api_key_dict.parent_otel_span,
check_db_only=True,
)
except HTTPException:
_key_team = None
validate_logging_exporter_field(
data.logging_exporters,
user_api_key_dict,