From fd5616f8ab01d52f5b4e21f23bf42b3efb4dac67 Mon Sep 17 00:00:00 2001
From: mateo-berri <277851410+mateo-berri@users.noreply.github.com>
Date: Thu, 28 May 2026 06:10:46 +0000
Subject: [PATCH] fix(compact_20260112): distinguish access-denied from
transient errors; greedy summary regex
- _check_summary_model_access now catches ProxyException explicitly for access
denials and logs unexpected exceptions separately. Both still fail closed,
but operators can now tell a denied key/team apart from a router internal
raising during the check.
- _SUMMARY_TAG_RE switches from non-greedy to greedy so a stray
inside the model's summary content no longer silently truncates the
captured text.
---
.../context_management/editors/compact.py | 41 ++++++++++---------
1 file changed, 22 insertions(+), 19 deletions(-)
diff --git a/litellm/llms/anthropic/experimental_pass_through/context_management/editors/compact.py b/litellm/llms/anthropic/experimental_pass_through/context_management/editors/compact.py
index 5959ed38655..63b685fb4e5 100644
--- a/litellm/llms/anthropic/experimental_pass_through/context_management/editors/compact.py
+++ b/litellm/llms/anthropic/experimental_pass_through/context_management/editors/compact.py
@@ -52,7 +52,7 @@ _PROPAGATED_METADATA_KEYS = (
"litellm_parent_otel_span",
)
-_SUMMARY_TAG_RE = re.compile(r"(.*?)", re.IGNORECASE | re.DOTALL)
+_SUMMARY_TAG_RE = re.compile(r"(.*)", re.IGNORECASE | re.DOTALL)
def _read_summary_model_setting() -> Optional[str]:
@@ -80,11 +80,15 @@ def _check_summary_model_access(
Returns True (allow) when ``user_api_key_auth`` is not present — SDK
callers and tests run outside the proxy, where no key/team policy exists.
Returns False when either the key-level or team-level allowlist denies
- the summary model.
+ the summary model (``ProxyException`` from ``_can_object_call_model``).
+ Unexpected errors during the check (e.g. router internals raising) fail
+ closed but are logged separately so operators can distinguish them from
+ a real access-denied response.
"""
if user_api_key_auth is None:
return True
try:
+ from litellm.proxy._types import ProxyException
from litellm.proxy.auth.auth_checks import _can_object_call_model
except Exception:
return True
@@ -92,31 +96,30 @@ def _check_summary_model_access(
key_models = list(getattr(user_api_key_auth, "models", None) or [])
team_id = getattr(user_api_key_auth, "team_id", None)
team_model_aliases = getattr(user_api_key_auth, "team_model_aliases", None)
- if key_models:
- try:
- _can_object_call_model(
- model=summary_model,
- llm_router=llm_router,
- models=key_models,
- team_model_aliases=team_model_aliases,
- team_id=team_id,
- object_type="key",
- )
- except Exception:
- return False
-
team_models = list(getattr(user_api_key_auth, "team_models", None) or [])
- if team_models:
+
+ for object_type, models in (("key", key_models), ("team", team_models)):
+ if not models:
+ continue
try:
_can_object_call_model(
model=summary_model,
llm_router=llm_router,
- models=team_models,
+ models=models,
team_model_aliases=team_model_aliases,
team_id=team_id,
- object_type="team",
+ object_type=object_type,
+ )
+ except ProxyException:
+ return False
+ except Exception as e:
+ verbose_logger.warning(
+ "compact_20260112: unexpected error during %s-level access "
+ "check for summary_model=%s; denying access: %s",
+ object_type,
+ summary_model,
+ e,
)
- except Exception:
return False
return True