litellm/tests/test_litellm/proxy/credential_endpoints
Yucheng Zhu 33b35e83df revert(credentials): drop handler authz gate, rely on route authorization
The prior commit gated credential management on credential_type at the handler
(trace destinations proxy-admin-only). That is more machinery than the case warrants:
/credentials is already governed by route authorization, so a non-admin reaches it
only when an admin explicitly delegates the route via allowed_routes, which is the
admin's decision to make.

Remove the handler-level authorization entirely (create/update/delete/list/by_name)
so credential access matches base: the proxy admin, or a key delegated /credentials
via allowed_routes, manages any credential; a plain non-admin key is still blocked at
route auth. The destinations feature adds logging-typed credentials to the store
without changing who may manage the store. Keeps the access-shape validation, the
partial-PATCH access merge, and otel_headers masking.
2026-07-29 16:51:41 -07:00
..
test_endpoints.py revert(credentials): drop handler authz gate, rely on route authorization 2026-07-29 16:51:41 -07:00