mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-30 01:52:18 +00:00
* fix: enforce MCP toolsets attached to a team, org, or internal user object_permission.mcp_toolsets was resolved into servers and tools only at the key level; every other principal read mcp_tool_permissions and silently ignored its toolsets. A team/org/user toolset alongside a server grant was inert (all tools callable), a toolset alone granted nothing, and an inert team toolset let the org server list substitute for the empty team result, handing the caller every org server. Resolve toolsets at each level that resolves mcp_tool_permissions, union their servers into that level's granted server set, and count a declared key/team toolset toward has_lower_level_mcp_restrictions so the org list can only cap, never substitute, even when the toolset resolves empty. Resolves LIT-5749 * fix: deny when a team's declared MCP toolset cannot be resolved The team server resolver swallowed UnloadableEntitlementError into an empty list, so a dangling team toolset dropped the team ceiling instead of denying, unlike the org and user paths. Re-raise it so the top-level resolver denies. Also anchor the test-quality suppression comments on the patch opener lines the gate reads, with per-seam reasons. |
||
|---|---|---|
| .. | ||
| mcp_server | ||