The /v1/messages/count_tokens proxy endpoint was only passing `messages`
to provider token counting APIs, discarding `system` and `tools`. This
caused clients like Claude Code to receive artificially low token counts
(e.g. 10 instead of 531), preventing proper context window management
and leading to context overflow errors.
Pass system and tools through the full chain:
- TokenCountRequest → proxy_server → provider counters → API handlers
- Bedrock: transform tools to toolConfig format, system to text blocks
- Anthropic/Azure AI: pass through directly (same API format)
Fixes#22285 — extra_headers passed to litellm.image_generation() were
silently dropped on the openai/litellm_proxy/openai_compatible_providers
code path. The azure and azure_ai paths already forwarded them correctly.
Extend the null normalization to access_model_names, access_mcp_server_ids,
and access_agent_ids in addition to assigned_team_ids and assigned_key_ids.
Writing null for non-optional list fields causes ValidationError on read.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
When a client sends null for assigned_team_ids or assigned_key_ids, ensure
the DB receives [] instead of null, preventing null from being stored where
empty list is expected. Extend test to verify the DB call uses [].
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
set(None) raises TypeError when a client sends null for assigned_team_ids or
assigned_key_ids. Add `or []` to handle null safely, consistent with create.
Add test covering this case.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Initialize teams_to_add/teams_to_remove/keys_to_add/keys_to_remove before
the try block in update_access_group for defensive clarity
- In delete_access_group, update teams/keys returned by find_many directly
(data already fetched) and use _sync_remove only for out-of-sync entities
not found by the hasSome query, eliminating N+1 find_unique calls
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Eliminates TOCTOU race where existing record was read outside the
transaction, allowing a concurrent update to make delta computation stale.
Delta is now computed atomically within the same transaction as the write.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
When creating, updating, or deleting access groups, automatically keep
team and key access_group_ids in sync with the access group's assigned_team_ids
and assigned_key_ids. Includes transaction-based DB updates, cache patching,
and handles out-of-sync data by unioning assigned_* fields with hasSome queries.
Adds 12 new tests covering sync behavior across all three CRUD operations.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>