litellm/tests/test_litellm/proxy/auth
yassin e02f19fdd9 fix(auth): exempt the reserved UI session team from the absent-team refusal
Every Admin UI session key is stamped with team_id=litellm-dashboard, a reserved
sentinel that /team/new refuses to create, so resolving it against the database can
only fail. The absent-versus-unreadable distinction #36837 added read that as a
deleted team and 404'd every dashboard request. Resolve the sentinel from the token
instead of asking for a row that will never exist.

The reserved id alone does not earn the exemption. The synthesized team's empty
models reads as every model, so an identity that merely names the sentinel is
widened rather than waved through, and several auth paths take team_id straight
from data the proxy did not mint: JWT claims, an OAuth2 introspection response, a
custom auth handler's return value. Rather than enumerate the producers to exclude,
require proof of where the credential came from. A database-minted session key is
already marked as a virtual key. The EXPERIMENTAL_UI_LOGIN blob has no key row, and
a proxy-admin one returns before the virtual-key paths, so mark it where it is
decrypted with the proxy's own ui_hash_key. Both markers are stripped from validated
input, so no claim, header or handler return can carry one in.

That leaves the id itself, which /team/new reserves but key creation did not, so a
proxy admin could put an ordinary key on the sentinel team and it would inherit the
exemption along with the skip of its owner's user-level model check. Reserve the id
on the key create and update paths too. The UI mints its session key through
generate_key_helper_fn directly, so it never passes through either one.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-08-14 16:43:17 -07:00
..
test_admin_viewer_handler_access.py feat(proxy): add GET /management/v1/budgets (#35310) 2026-07-31 11:47:05 -07:00
test_auth_checks.py fix(auth): stop the team fallback from widening model access (#36837) 2026-08-13 16:59:58 -07:00
test_auth_exception_handler.py fix(proxy): only treat a recoverable database outage as grounds to serve without one (#35864) 2026-08-05 14:15:13 -07:00
test_auth_hot_path_network_requests.py perf(auth): negative-cache missing user/key lookups on the request hot path (#32368) 2026-07-08 09:59:57 +03:00
test_auth_utils.py fix(proxy): ban caller-supplied aws identity selectors in request bodies 2026-08-10 22:05:49 -07:00
test_banned_params_extra_body.py fix(proxy): ban caller-supplied aws identity selectors in request bodies 2026-08-10 22:05:49 -07:00
test_cli_auth.py fix(cli): surface actionable CLI SSO errors when CLI and proxy versions skew (#33309) 2026-07-15 10:17:40 -07:00
test_custom_auth_end_user_budget.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_handle_jwt.py fix(jwt_auth): grant only /v1/messages routes to JWT teams by default, not all anthropic_routes 2026-07-27 17:15:09 -07:00
test_info_routes.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_litellm_license.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_login_utils.py feat(mcp): gateway DCR session admission at the aggregate /mcp endpoint (LIT-3637) 2026-07-23 00:24:28 -07:00
test_mcp_ip_filtering.py feat(mcp): add mcp_xff_num_trusted_hops to harden X-Forwarded-For client IP resolution (#31257) 2026-06-25 07:31:29 -07:00
test_model_checks.py fix(proxy): expand config-defined model access groups when resolving team models for /v2/model/info (#34211) 2026-08-12 12:54:36 -07:00
test_model_checks_fallbacks.py perf: build log messages lazily so filtered-out log records cost nothing (#35703) 2026-08-04 04:34:52 +00:00
test_multi_budget_windows.py fix(proxy): enforce budgets against authoritative DB spend when the cross-pod counter is unreliable (#30684) 2026-06-18 10:35:41 -07:00
test_network.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_oauth2_proxy_hook.py chore(auth): require trusted proxy for header identity auth 2026-04-29 21:20:21 -07:00
test_object_permission_loading.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_onboarding.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_organization_budget_enforcement.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_password_hashing.py chore: fixes 2026-03-30 18:36:58 -07:00
test_resolvers_exceptions.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_resolvers_models.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_resolvers_seam.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_resolvers_store.py feat(auth): resolve caller identity once into a Principal at the auth seam (#30887) 2026-06-20 18:49:41 -07:00
test_route_checks.py fix(proxy): allow non-admins to reach /user/daily/activity/aggregated 2026-08-05 23:24:37 -07:00
test_router_override_fallback_auth.py chore(proxy): clean up request parameter validation and provider destination handling (#34189) 2026-07-22 00:57:58 +00:00
test_team_member_budget.py Fix team member budget enforcement without user row (#27273) 2026-05-06 11:42:29 -07:00
test_unmapped_model_budget_enforcement.py fix(router): never price a strategy-router alias (#36691) 2026-08-12 14:26:30 -07:00
test_user_api_key_auth.py fix(auth): exempt the reserved UI session team from the absent-team refusal 2026-08-14 16:43:17 -07:00