litellm/backend/routes
derhornspieler b0a28b2e09 fix(proxy): let only proxy admins persist Anthropic workload identity fields
These fields pick which server-side secret is read and where the resulting assertion is
sent, so a team admin who can otherwise manage a team-scoped deployment must not be able
to set them. The create, update and patch model paths and both credential write paths now
reject them for anyone below proxy admin, mirroring the existing blocked-flag gate. The
field list is derived from anthropic_wif_litellm_params rather than copied, so a new
federation field is covered the day it is added

Also fixes two things CI caught: credential_values_to_delete is a PATCH instruction rather
than part of the credential, so it stays out of dumps that feed config loading and the
Prisma write, and the provider discovery route is registered in the backend allowlist
2026-08-23 12:42:23 -04:00
..
__init__.py feat: add componentized proxy deployment with gateway, backend, ui, and migrations (#27557) 2026-05-16 09:25:17 -07:00
allowlist.py fix(proxy): let only proxy admins persist Anthropic workload identity fields 2026-08-23 12:42:23 -04:00