mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
When `default_internal_user_params` was set, `insert_sso_user()` only preserved SSO-provided roles if `role_mappings` was explicitly configured. Roles from other valid SSO sources (Microsoft app_roles, GENERIC_USER_ROLE_ATTRIBUTE, custom SSO handlers) were silently overwritten with the default "internal_user" role, causing admin users to be downgraded on first login or after user deletion. Replace the `role_mappings_configured` gate with `_should_use_role_from_sso_response()` which validates the role is a recognized LitellmUserRoles value regardless of origin. Also removes an unnecessary DB round-trip to litellm_ssoconfig on every new SSO user creation. Fixes: admin users seeing internal-user UI after SSO login Fixes: test_get_redirect_url_for_sso flaking due to local env vars Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| scim | ||
| search_endpoints | ||
| test_access_group_endpoints.py | ||
| test_access_group_management.py | ||
| test_budget_endpoints.py | ||
| test_cache_settings_endpoints.py | ||
| test_callback_management_endpoints.py | ||
| test_common_daily_activity.py | ||
| test_common_utils.py | ||
| test_cost_tracking_settings.py | ||
| test_customer_budget.py | ||
| test_customer_endpoints.py | ||
| test_delete_callbacks_endpoint.py | ||
| test_entraid_app_roles.py | ||
| test_internal_user_endpoints.py | ||
| test_key_management_endpoints.py | ||
| test_mcp_management_endpoints.py | ||
| test_model_management_endpoints.py | ||
| test_organization_endpoints.py | ||
| test_router_settings_endpoints.py | ||
| test_tag_management_endpoints.py | ||
| test_team_endpoints.py | ||
| test_ui_sso.py | ||