From e5760dc2657f194dd3707f7e04cdd55a654d9e3a Mon Sep 17 00:00:00 2001 From: Yucheng Zhu Date: Tue, 28 Jul 2026 10:06:47 -0700 Subject: [PATCH] fix(otel/v2): drop dead team lookups flagged in review The /key/update path fetched the key's team into _key_team only to feed the team-admin/org-admin assignment flags removed in the admin-only refactor; it is now unused, so drop the wasted DB round-trip. The resolver's org lookup passed check_db_only=True, forcing a synchronous DB query on every team-key request even though the team is already resident in the cache from auth; drop it so the lookup is cache-first. Also correct two comments that still claimed team or org admins may assign logging_exporters. --- litellm/proxy/litellm_pre_call_utils.py | 1 - .../key_management_endpoints.py | 32 ++++--------------- 2 files changed, 7 insertions(+), 26 deletions(-) diff --git a/litellm/proxy/litellm_pre_call_utils.py b/litellm/proxy/litellm_pre_call_utils.py index d6d06d2e745..8223096892e 100644 --- a/litellm/proxy/litellm_pre_call_utils.py +++ b/litellm/proxy/litellm_pre_call_utils.py @@ -614,7 +614,6 @@ async def _effective_org_id(user_api_key_dict: UserAPIKeyAuth) -> str | None: prisma_client=proxy_server.prisma_client, user_api_key_cache=proxy_server.user_api_key_cache, parent_otel_span=getattr(user_api_key_dict, "parent_otel_span", None), - check_db_only=True, ) except HTTPException: return None diff --git a/litellm/proxy/management_endpoints/key_management_endpoints.py b/litellm/proxy/management_endpoints/key_management_endpoints.py index 4b132da1e2e..d509d9647d4 100644 --- a/litellm/proxy/management_endpoints/key_management_endpoints.py +++ b/litellm/proxy/management_endpoints/key_management_endpoints.py @@ -1648,10 +1648,8 @@ async def generate_key_fn( route=KeyManagementRoutes.KEY_GENERATE, ) - # Team-admin of the key's team or org-admin of that team's org may assign - # logging_exporters on team-owned keys. Personal keys (no team_table) stay - # proxy-admin only. Skip the role lookup when the field isn't in the payload - # to keep /key/generate cheap for the common case. + # logging_exporters on a key is proxy-admin only. Skip the check when the + # field isn't in the payload to keep /key/generate cheap for the common case. if data.logging_exporters is not None: validate_logging_exporter_field(data.logging_exporters, user_api_key_dict) @@ -1832,10 +1830,8 @@ async def generate_service_account_key_fn( route=KeyManagementRoutes.KEY_GENERATE_SERVICE_ACCOUNT, ) - # Same logging_exporters gate as /key/generate. Without this, a caller - # eligible for service-account creation could set metadata.logging_exporters - # and route future traces to a destination they aren't allowed to assign - # (Veria F3). Skip the lookup unless the field is being written. + # Same logging_exporters gate as /key/generate: proxy-admin only. Skip the + # check unless the field is being written. from litellm.proxy.management_endpoints.logging_exporter_validation import ( validate_logging_exporter_field, ) @@ -2627,24 +2623,10 @@ async def update_key_fn( # noqa: C901 # single endpoint handling many optional prisma_client=prisma_client, ) - # logging-exporters validation runs once the key's team is known so a - # team-admin or org-admin of that team can attach destinations. The - # validator no-ops when the effective value doesn't change; pass the - # stored column value so a non-admin cannot clear an admin-assigned one. + # logging_exporters is proxy-admin only. The validator no-ops when the + # effective value doesn't change; pass the stored column value so a + # non-admin cannot clear an admin-assigned one. if data.logging_exporters is not None: - _key_team_id = getattr(existing_key_row, "team_id", None) - _key_team = None - if _key_team_id is not None: - try: - _key_team = await get_team_object( - team_id=_key_team_id, - prisma_client=prisma_client, - user_api_key_cache=user_api_key_cache, - parent_otel_span=user_api_key_dict.parent_otel_span, - check_db_only=True, - ) - except HTTPException: - _key_team = None validate_logging_exporter_field( data.logging_exporters, user_api_key_dict,