- Fix unknown permissions duplication: seed selected state with only known
permissions so existingUnknown and selected are disjoint on save
- Disable Add MCP Server button for non-admins without a team selected,
show tooltip explaining they need to select a team first
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Separate save failure from refresh failure: close drawer after successful
save even if teamInfoCall refresh fails
- Preserve unknown permissions not in availablePermissions when saving,
preventing silent drops of permissions from newer backend versions
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Type onUpdate as () => Promise<void> and await it before closing drawer
- Replace accessToken! assertion with explicit null guard
- Gate fetchAvailableTeamMemberPermissions behind canEditTeam check
- Pass team_id for admins too when a team is selected in the filter
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add UI support for the MCP team management permissions introduced in PR #24266.
- Add MemberPermissionsDrawer component (Ant Design Drawer) for managing
per-member MCP permissions (mcp:read, mcp:create, mcp:update, mcp:delete)
- Add permissions button to team member table actions column
- Fetch available permissions from GET /team/available_permissions
- Pass extra_permissions in team member update API calls
- Allow all users to create MCP servers directly (backend enforces permissions)
- Pass team_id when non-admin users create MCP servers
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Move callbacks outside try/catch so only mutation errors are caught,
not errors from onVersionCreated/onVersionStatusUpdated callbacks
- Replace policyName! non-null assertion with DISABLED_POLICY_KEY
sentinel to avoid undefined in cache keys when query is disabled
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add PolicyVersionsData type for select output; specify TData generic
so consumers get Policy[] (not Policy[] | undefined) for versions
- Remove empty-string queryKey fallback — use policyName! since
enabled:false prevents fetch when policyName is null
- Add cache invalidation tests for both mutation hooks
- Add explanatory comment for ?? [] fallback in component
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Make PolicyVersionsResponse.versions optional (Policy[] | undefined)
to match real API shape — select fallback handles normalization
- Add policyName guard to useUpdatePolicyVersionStatus mutationFn
to fail loudly instead of silently skipping cache invalidation
- Add test for null policyName in updateStatus mutation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Wrap mutateAsync calls in try/catch to swallow re-thrown errors
(notifications already handled by onError in mutation hooks)
- Use isLoading instead of isPending for version loading state —
isPending is true when query is disabled with no cache, isLoading
is only true during active fetches (matches original behavior)
- Add isLoading assertions to disabled-state tests
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Move extra_permissions validation before budget upsert to prevent
partial DB writes on validation failure
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Revert PUT /v1/mcp/server status code to 202 (backwards-compatible)
- Strengthen Member.extra_permissions validator to check VALID_PERMISSIONS
- Invalidate team cache after add/remove_mcp_server_to_team
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Handle ValueError on team-link failure as 400 (orphaned server fix)
- Wrap delete's remove_from_team in try/except (prevent 500 after
successful delete)
- Revert DELETE status code to 202 (backwards-compatible)
- Add extra_permissions to TeamMemberUpdateResponse
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Wrap add/remove_mcp_server_to_team in DB transactions (race condition fix)
- Consolidate role + extra_permissions into single DB write (atomicity)
- Remove silent try/except on team linking (surface errors to caller)
- Add email fallback to _find_member_in_team (email-only members)
- Add None guard on payload.server_id in update endpoint
- Add field_validator on Member.extra_permissions (resource:action format)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Ensures permission changes take effect immediately instead of waiting
for cache TTL expiry.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Allow team admins and permissioned members to manage MCP servers scoped
to their team, laying groundwork for full Permission Strings RBAC.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace useEffect + useState fetch pattern for policy version management
with React Query hooks (useQuery + useMutation), following established
codebase conventions.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Added a new section to the config.yaml documentation explaining how to
set the LITELLM_LICENSE environment variable for enterprise features.
Co-authored-by: Krish Dholakia <krrishdholakia@gmail.com>
Tests were outdated after _get_and_validate_existing_key was refactored
to use prisma_client.db.litellm_verificationtoken.find_unique() and
ProxyException. Also add ProxyException handling in bulk_update_keys
error extractor so error messages aren't empty.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Tests were outdated after _get_and_validate_existing_key was refactored
to use prisma_client.db.litellm_verificationtoken.find_unique() instead
of prisma_client.get_data(), and to raise ProxyException instead of
HTTPException. Also fix bulk_update_keys error handler to extract
ProxyException.message (str(ProxyException) returns empty string).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>