This fixes the issue where JWT auth was not selecting teams for MCP routes
because MCP routes were not in the default team_allowed_routes.
The flow was:
1. JWT auth calls find_team_with_model_access()
2. find_team_with_model_access checks allowed_routes_check() for the route
3. For MCP routes like /mcp/tools/list, this check FAILED because
team_allowed_routes only included 'openai_routes' and 'info_routes'
4. Team was NOT selected, team_id was None
5. MCP permission lookup returned empty because team_id was None
The fix adds 'mcp_routes' to the default team_allowed_routes so that:
- Teams can be selected when accessing MCP endpoints
- Team MCP permissions (from object_permission.mcp_servers) are enforced
This is the second part of the fix for JWT + MCP permission enforcement.
The first part (allowing teams with models=None) was in the previous commit.
Changes:
- LiteLLM_JWTAuth.team_allowed_routes: Added 'mcp_routes' to default list
- allowed_routes_check: Updated fallback to also include 'mcp_routes'
- Added test_jwt_auth_allows_mcp_routes_for_teams to verify the fix
Co-authored-by: ishaan <ishaan@berri.ai>
This test documents the complete flow from JWT authentication to MCP permission
enforcement:
1. Team with models=None and MCP servers in object_permission
2. JWT has team in groups (team_ids_jwt_field)
3. Team is selected (after fix) and team_id is set on UserAPIKeyAuth
4. MCP permission lookup uses team_id to find team's object_permission.mcp_servers
This test ensures the fix for JWT + MCP permission enforcement is working correctly.
Co-authored-by: ishaan <ishaan@berri.ai>
This fixes an issue where MCP permission management was not working with JWTs.
When a team has MCPs assigned via object_permission.mcp_servers but has
models=None (no model restrictions), the team would be skipped during
JWT authentication because find_team_with_model_access required
team.models to not be None.
The fix treats models=None as 'no model restrictions' (allow all models),
which is consistent with how models=[] (empty list) is handled elsewhere
in the codebase.
This allows users with JWTs containing team IDs in their groups claim to
properly have their team's MCP permissions enforced.
Changes:
- Modified find_team_with_model_access to allow teams with models=None
- Added tests to verify the new behavior:
- test_find_team_with_model_access_models_none: teams with models=None selected
- test_find_team_with_model_access_models_none_with_model_requested: any model allowed
- test_find_team_with_model_access_empty_models_list: existing behavior preserved
Co-authored-by: ishaan <ishaan@berri.ai>
* Add LangSmith mock client support
- Create langsmith_mock_client.py following GCS and Langfuse patterns
- Add mock mode detection via LANGSMITH_MOCK environment variable
- Intercept LangSmith API calls via AsyncHTTPHandler.post patching
- Add verbose logging throughout mock implementation
- Update LangsmithLogger to initialize mock client when mock mode enabled
- Supports configurable mock latency via LANGSMITH_MOCK_LATENCY_MS
* Add Datadog mock client support
- Create datadog_mock_client.py following GCS, Langfuse, and LangSmith patterns
- Add mock mode detection via DATADOG_MOCK environment variable
- Intercept Datadog API calls via AsyncHTTPHandler.post and httpx.Client.post patching
- Add verbose logging throughout mock implementation
- Update DataDogLogger and DataDogLLMObsLogger to initialize mock client when mock mode enabled
- Supports both async and sync logging paths
- Supports configurable mock latency via DATADOG_MOCK_LATENCY_MS
* refactor: consolidate mock client logic into factory pattern
- Create mock_client_factory.py to centralize common mock HTTP client logic
- Refactor GCS, Langfuse, LangSmith, and Datadog mock clients to use factory
- Improve GET/DELETE mock accuracy for GCS (return valid StandardLoggingPayload)
- Fix DELETE mock to return empty body (204 No Content) instead of JSON
- Reduce code duplication across integration mock clients
* feat: add PostHog mock client support
- Create posthog_mock_client.py using factory pattern
- Integrate mock client into PostHogLogger with mock mode detection
- Add verbose logging for mock mode initialization and batch operations
- Enable mock mode via POSTHOG_MOCK environment variable
* Add Helicone mock client support
- Created helicone_mock_client.py using factory pattern (similar to GCS)
- Integrated mock mode detection and initialization in HeliconeLogger
- Mock client patches HTTPHandler.post to intercept Helicone API calls
- Uses factory pattern for should_use_mock and MockResponse utilities
- Custom HTTPHandler.post patching required since HTTPHandler uses self.client.send()
* Add mock support for Braintrust integration and extend mock client factory
- Add braintrust_mock_client.py with mock HTTP client for Braintrust integration testing
- Integrate mock client into BraintrustLogger with mock mode detection
- Refactor Helicone mock client to fully utilize factory's HTTPHandler.post patching
- Extend mock_client_factory to support patching HTTPHandler.post for sync calls
- Enable endpoint-specific mock responses for Braintrust (/project vs /project_logs)
- All mock clients now properly handle both async (AsyncHTTPHandler) and sync (HTTPHandler) calls
* Fix linter errors: remove unused imports and suppress complexity warning
- Remove unused imports from gcs_bucket_mock_client.py (httpx, json, timedelta, Dict, Optional)
- Remove unused Callable import from mock_client_factory.py
- Add noqa comment to suppress PLR0915 complexity warning for create_mock_client_factory function
* Document mock environment variables for PostHog, Helicone, Braintrust, Datadog, and Langsmith integrations
- Add POSTHOG_MOCK and POSTHOG_MOCK_LATENCY_MS documentation
- Add HELICONE_MOCK and HELICONE_MOCK_LATENCY_MS documentation
- Add BRAINTRUST_MOCK and BRAINTRUST_MOCK_LATENCY_MS documentation
- Add DATADOG_MOCK and DATADOG_MOCK_LATENCY_MS documentation
- Add LANGSMITH_MOCK and LANGSMITH_MOCK_LATENCY_MS documentation
All mock env vars follow the same pattern: enable mock mode for integration testing by intercepting API calls and returning mock responses without making actual network calls.
* Fix security issue
Fixes permission error where prisma generate fails with 'Permission denied'
when trying to write schema.prisma in non-root containers.
The issue was that prisma generate was running as root before switching
to nobody user, causing generated files to be owned by root:root.
Moving prisma generate after USER nobody ensures files are owned by
nobody:nobody and can be written to during runtime.
Fixes#19859
* fix: bedrock invoke - does not support prompt-caching-scope
* fix: UNSUPPORTED_BEDROCK_INVOKE_BETA_PATTERNS
* init requirements.txt
* init README for claude Agent SDK
* fix: using converse models with UNSUPPORTED_BEDROCK_CONVERSE_BETA_PATTERNS
* fix main.py
* init: proxy_e2e_anthropic_messages_tests