Commit graph

36546 commits

Author SHA1 Message Date
Ishaan Jaffer
1736f8ced7 feat(ui): add Team Member Settings accordion to Create Team modal
Groups default_team_member_models, member budget/key duration, and
tpm/rpm defaults into a single collapsible section. The model picker
is filtered to only show the models selected for the team, and the
copy distinguishes it from the team-level Models field.
2026-04-01 16:29:10 -07:00
Ishaan Jaffer
ed9009347b fix(auth): pass llm_router to _check_team_member_model_access
Without the router, _can_object_call_model cannot resolve wildcard model
names (e.g. openai/*) or access-group names in allowed_models, causing
legitimate requests to be denied.  Thread the existing llm_router from
_run_common_checks through to the new member-scope check.
2026-04-01 16:20:25 -07:00
Ishaan Jaffer
48ecd59aa5 fix(team_member_update): update existing budget in-place instead of creating new one
When a member already has a budget_id, patch only the fields the caller
provided rather than always creating a fresh budget record.  The old
code ignored existing_budget_id entirely, so updating only allowed_models
silently dropped the stored max_budget / tpm_limit / rpm_limit values.
2026-04-01 16:20:25 -07:00
github-actions[bot]
1814fd64b0 chore: sync schema.prisma copies from root 2026-04-01 22:38:06 +00:00
Ishaan Jaffer
2decf5f8b6 TeamInfo: add default_team_member_models field in Settings tab 2026-04-01 15:37:03 -07:00
Ishaan Jaffer
77ca095412 EditMembership: add Allowed Models multi-select field 2026-04-01 15:37:03 -07:00
Ishaan Jaffer
19b105b00d TeamMemberTab: add Model Scope column showing per-member allowed_models 2026-04-01 15:37:03 -07:00
Ishaan Jaffer
0bcd16f470 networking: add allowed_models to Member type and teamMemberUpdateCall 2026-04-01 15:36:55 -07:00
Ishaan Jaffer
626966a4a5 auth: enforce per-member allowed_models at request time 2026-04-01 15:36:43 -07:00
Ishaan Jaffer
066771143f team endpoints: seed allowed_models on member_add, persist on member_update and team/update 2026-04-01 15:36:15 -07:00
Ishaan Jaffer
0891c13429 common_utils: add allowed_models to _upsert_budget_and_membership 2026-04-01 15:35:07 -07:00
Ishaan Jaffer
5361579640 utils: add allowed_models param to add_new_member, persist to budget table 2026-04-01 15:34:44 -07:00
Ishaan Jaffer
2e119c8500 types: add allowed_models to TeamMemberAddRequest, TeamMemberUpdateRequest, UpdateTeamRequest 2026-04-01 15:32:26 -07:00
Ishaan Jaffer
45dc6f5eba migration: add allowed_models and default_team_member_models columns 2026-04-01 15:32:12 -07:00
Ishaan Jaffer
fcf08a6e36 schema: add allowed_models to BudgetTable, default_team_member_models to TeamTable 2026-04-01 15:32:08 -07:00
Ishaan Jaffer
a73a944abc test(bedrock): add test for [1m] context window suffix stripping in cost lookup 2026-04-01 12:17:08 -07:00
Ishaan Jaffer
440c3387df fix(bedrock): strip [1m]/[200k] context window suffixes before cost lookup 2026-04-01 12:16:54 -07:00
ishaan-berri
e4442a4d98
test fix us.anthropic.claude-haiku-4-5-20251001-v1:0 (#24931)
* test fix us.anthropic.claude-haiku-4-5-20251001-v1:0

* ignore mypy cache files

---------

Co-authored-by: Ishaan Jaffer <ishaanjaffer0324@gmail.com>
Co-authored-by: David Chen <clfhhc@gmail.com>
2026-04-01 11:01:03 -07:00
David Chen
c987bdba84
fix lint problem (#24932) 2026-04-01 10:24:37 -07:00
yuneng-jiang
0f88968da9
Merge pull request #24804 from joereyna/feat/add-codecov-to-ci
Re-add Codecov coverage reporting to GHA matrix workflow
2026-04-01 09:46:55 -07:00
michelligabriele
283375f4d6
fix(proxy): eliminate race condition in streaming guardrail_information logging (#24592)
asyncio.create_task in CSW.__anext__ scheduled the deferred logging
callback as an independent task that raced with unified_guardrail's
end-of-stream block. For short-stream providers (Vertex AI, Azure,
Anthropic), the logging fired before guardrail_information was written,
causing post_call guardrail entries to be missing from
StandardLoggingPayload.

Move the deferred callback trigger from CSW.__anext__ to
ProxyLogging.async_post_call_streaming_iterator_hook (after the full
streaming pipeline completes). CSW now stores the assembled response
args; the outer consumer fires the callback after all guardrail
end-of-stream blocks finish. Also skip apply_guardrail guardrails in
_run_deferred_stream_guardrails to eliminate duplicate API calls.
2026-04-01 08:06:56 -07:00
yuneng-jiang
33c3f13443
Merge pull request #24880 from stuxf/fix/codeql-ui-alerts
fix: resolve CodeQL high-severity alerts in UI components
2026-03-31 18:23:56 -07:00
ryan-crabbe-berri
2f1cfb0548
Merge pull request #24751 from BerriAI/litellm_ryan-march-28
litellm ryan march 28
2026-03-31 17:25:30 -07:00
yuneng-jiang
a320dcc198
Merge pull request #24881 from BerriAI/litellm_release_action
[Infra] Add release workflow with cosign verification
2026-03-31 17:08:04 -07:00
joereyna
c903845266
Use unique filenames per matrix job to preserve all coverage reports 2026-03-31 16:44:13 -07:00
joereyna
98a51e088d
Remove debug step from upload-coverage job 2026-03-31 16:44:13 -07:00
joereyna
695d726352
Revert to --cov=litellm, add checkout and root_dir to upload job 2026-03-31 16:44:13 -07:00
joereyna
b8eac3059a
Measure coverage from repo root so filenames include litellm/ prefix 2026-03-31 16:44:13 -07:00
joereyna
fdfd0e58ed
Force coverage path remapping via explicit coverage xml step 2026-03-31 16:44:13 -07:00
joereyna
57c22d3a41
Add debug step to inspect coverage XML paths 2026-03-31 16:44:13 -07:00
joereyna
0687ebb130
Fix coverage paths: use absolute->relative remapping for Codecov 2026-03-31 16:44:13 -07:00
joereyna
a8a3eb9d5b
Fix Codecov path prefix via fixes directive 2026-03-31 16:44:13 -07:00
joereyna
e7e0637f53
Fix coverage source paths for Codecov 2026-03-31 16:44:13 -07:00
joereyna
4d7045d981
Fix coverage path mismatch for Codecov 2026-03-31 16:44:13 -07:00
joereyna
b55b3cfc05
Add pytest-cov to poetry.lock 2026-03-31 16:44:13 -07:00
joereyna
13660572ca
Add pull-requests write permission for Codecov PR comments 2026-03-31 16:44:13 -07:00
joereyna
aaa5973b88
Use OIDC for Codecov upload instead of static token 2026-03-31 16:44:13 -07:00
joereyna
8358650660
Isolate Codecov upload into separate job to protect CODECOV_TOKEN 2026-03-31 16:44:13 -07:00
joereyna
b3eee71084
Pin codecov-action to immutable SHA (v5.5.4) 2026-03-31 16:44:12 -07:00
joereyna
d38498c3ef
Re-add Codecov coverage upload to GHA matrix workflow 2026-03-31 16:44:12 -07:00
ishaan-berri
94e0f44798
Merge pull request #24882 from BerriAI/worktree-piped-exploring-patterson
docs: JWT → Virtual Key Mapping guide
2026-03-31 16:34:47 -07:00
Ishaan Jaffer
cbb84b6650 docs: add mermaid sequence diagram for JWT → key resolution flow 2026-03-31 16:33:27 -07:00
Ishaan Jaffer
64ec11df8b docs: fix unused import, clarify Claude Code JWT env var 2026-03-31 16:32:17 -07:00
Ishaan Jaffer
f357177338 docs: add jwt_key_mapping to sidebar under Authentication 2026-03-31 16:31:27 -07:00
Ishaan Jaffer
d3175a8262 docs: link JWT → Virtual Key Mapping from token_auth page 2026-03-31 16:31:23 -07:00
Ishaan Jaffer
83546cc57d docs: JWT → Virtual Key Mapping guide 2026-03-31 16:31:20 -07:00
Yuneng Jiang
8071691ffc
[Fix] Address review feedback on release workflow
- Use nullish coalescing for potentially null response body
- Create release as draft first, then publish atomically to avoid partial-release state
- Pin cosign.pub URL to release tag instead of main branch

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 16:26:20 -07:00
user
d12f8490bf
fix: resolve CodeQL high-severity alerts in UI components
Source fixes:
- page.tsx: add explicit isValidReturnUrl() check at redirect site
- public_model_hub.tsx: replace() → replaceAll() for all wildcard occurrences
- CodeSnippets.tsx: escape backslashes before quotes in generated Python
- TeamGuardrailsTab.tsx: escape backslashes before quotes in generated YAML

CodeQL suppressions for false positives:
- ChatUI.tsx: sessionStorage for apiKey/apiKeySource (sessionStorage is
  correct per project policy — scoped to tab, cleared on close)
- ChatUI.tsx: setInputMessage(prompt) where prompt is a hardcoded literal
- mcp_server_edit.tsx, create_mcp_server.tsx: sessionStorage for OAuth state
- useMcpOAuthFlow.tsx, useUserMcpOAuthFlow.tsx: sessionStorage wrappers
- LoginPage.tsx: localStorage.getItem for worker URL in SSO flow

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 23:06:05 +00:00
Yuneng Jiang
05368d9b1a
[Infra] Add cosign verification section to release notes
Prepend Docker image signature verification instructions to auto-generated
release notes, using the cosign public key committed to the repo.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 15:46:34 -07:00
Ishaan Jaffer
5ebc7b53b4 docs fix 2026-03-31 14:46:13 -07:00