mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
* refactor(proxy): route every team-admin decision through auth/team_access.py Move the six team-admin helpers out of common_utils, team_endpoints and key_management_endpoints into litellm/proxy/auth/team_access.py under public names, and point every management route and helper at them. The key routes keep checking team admin before org admin, so a team admin whose user row is gone still passes as before. Status codes and bodies are unchanged, which the 223-case team-admin matrix confirms at the merge base and at the tip common_utils keeps `_is_user_team_admin` as an alias because the published litellm-enterprise 0.1.71 wheel still imports it from there * refactor(proxy): answer every team access check with TeamAccess.allows Replace the six helpers in auth/team_access.py with one resolver in litellm/proxy/management/teams/access.py. Each route passes the roles it accepts (TEAM_OR_ORG_ADMIN or TEAM_ADMIN_ONLY), and /team/update and /team/info rank roles through strongest_role so org admin still outranks team admin there The org lookup moves behind an OrgRoles protocol, implemented by PrismaOrgRoles in management/users/service.py, and get_team_access in management/teams/dependencies.py is the only place that reads proxy_server globals. _check_key_admin_access keeps its name and body from main Routes that checked org admin first now read the roster first, so a team admin whose org lookup errors now passes on /team/delete, /team/block, /team/unblock, member reset_spend and reset_budget, and the team callback routes. No allowed caller is denied |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| actors.py | ||
| conftest.py | ||
| test_credential_migration_endpoint.py | ||
| test_f7_coverage_closeout.py | ||
| test_f7_key_coverage_push.py | ||
| test_key_aliases.py | ||
| test_key_block_unblock.py | ||
| test_key_budget_limits.py | ||
| test_key_bulk_update.py | ||
| test_key_delete.py | ||
| test_key_generate.py | ||
| test_key_health.py | ||
| test_key_info.py | ||
| test_key_info_v2.py | ||
| test_key_list.py | ||
| test_key_regenerate.py | ||
| test_key_reset_spend.py | ||
| test_key_service_account_generate.py | ||
| test_key_team_change.py | ||
| test_key_update.py | ||
| test_no_management_imports.py | ||
| test_route_coverage.py | ||
| test_scratch_teardown.py | ||
| test_smoke.py | ||
| test_team_available.py | ||
| test_team_block_unblock.py | ||
| test_team_budget_limits.py | ||
| test_team_bulk_member_add.py | ||
| test_team_bulk_member_delete.py | ||
| test_team_daily_activity.py | ||
| test_team_delete.py | ||
| test_team_filter_ui.py | ||
| test_team_info.py | ||
| test_team_key_bulk_update.py | ||
| test_team_list.py | ||
| test_team_list_v2.py | ||
| test_team_member_add.py | ||
| test_team_member_delete.py | ||
| test_team_member_info_validation.py | ||
| test_team_member_me.py | ||
| test_team_member_reset_budget.py | ||
| test_team_member_reset_spend.py | ||
| test_team_member_update.py | ||
| test_team_metadata_schema.py | ||
| test_team_model.py | ||
| test_team_new.py | ||
| test_team_permissions.py | ||
| test_team_permissions_bulk_update.py | ||
| test_team_spend_by_user.py | ||
| test_team_update.py | ||
| test_users_bulk_delete.py | ||
| test_world_seed.py | ||