From ed9009347b2e51d5d93c073c63392cd924073032 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Wed, 1 Apr 2026 16:20:02 -0700 Subject: [PATCH] fix(auth): pass llm_router to _check_team_member_model_access Without the router, _can_object_call_model cannot resolve wildcard model names (e.g. openai/*) or access-group names in allowed_models, causing legitimate requests to be denied. Thread the existing llm_router from _run_common_checks through to the new member-scope check. --- litellm/proxy/auth/auth_checks.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/auth/auth_checks.py b/litellm/proxy/auth/auth_checks.py index a28304db6b9..25f85174ae4 100644 --- a/litellm/proxy/auth/auth_checks.py +++ b/litellm/proxy/auth/auth_checks.py @@ -435,6 +435,7 @@ async def common_checks( # noqa: PLR0915 model=_model, team_object=team_object, valid_token=valid_token, + llm_router=llm_router, prisma_client=prisma_client, user_api_key_cache=user_api_key_cache, proxy_logging_obj=proxy_logging_obj, @@ -3085,6 +3086,7 @@ async def _check_team_member_model_access( model: Union[str, List[str]], team_object: LiteLLM_TeamTable, valid_token: UserAPIKeyAuth, + llm_router: Optional[Router], prisma_client: Optional["PrismaClient"], user_api_key_cache: DualCache, proxy_logging_obj: ProxyLogging, @@ -3119,7 +3121,7 @@ async def _check_team_member_model_access( try: _can_object_call_model( model=model, - llm_router=None, + llm_router=llm_router, models=member_allowed_models, object_type="team", )