litellm/terraform
Louis Vauterin b9ba36c231
fix(provider): accept 2xx status codes in unified_access_group create (#42461)
* fix(provider): accept 2xx status in handleResponse for access group create

handleResponse (resource_team.go) only accepted exactly HTTP 200, but
POST /v1/access_group (and its /v1/unified_access_group alias) legitimately
answers 201 Created. litellm_access_group and litellm_unified_access_group
create both succeeded on the proxy and failed in the provider, leaving the
group out of state and forcing an import to recover on the next apply's
409 for the now-duplicate name.

Same fix and shape as #40723, which widened this exact check in
sendRequest/handleAPIResponse/handleMCPAPIResponse for mcp_server, model,
key and organization_member. handleResponse is the one shared status-check
helper that fix didn't reach -- it's a different function in a different
file (resource_team.go, not client.go/utils.go), so this is fully
independent of that PR and can land before, after, or alongside it with
no conflict.

handleResponse is also used by agent, budget, guardrail, organization,
prompt, search_tool, tag, team, team_block, key_block, team_member(_add)
and user -- all unaffected in practice, since every one of their own
endpoints already answers exactly 200. Widening the check costs them
nothing and only changes behavior for the two resources that were
actually broken.

Verified: go test ./... passes, including a new
TestHandleResponseAcceptsFullSuccessRange table test covering
200/201/202/204 (accepted) and 400/404/409/500 (still rejected), mirroring
#40723's own TestHandleAPIResponseAcceptsFullSuccessRange.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: address Greptile review on PR 42461

- CHANGELOG: narrowed the fix's scope to unified_access_group only.
  litellm_access_group (legacy) calls /access_group/new, a completely
  different, unrelated endpoint (model_access_group_management_endpoints.py)
  that already returns 200 -- it was never affected. I'd wrongly assumed
  both resources shared the same /v1/access_group route; they don't.
- resource_team_test.go: removed the preamble comment above the new test,
  which restated what the table test already shows -- against repository
  guidance (AGENTS.md) that reserves comments for complex logic, tool
  inputs, or TODOs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore: retrigger CI

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 13:54:37 -07:00
..
litellm fix(gateway): expose /api/event_logging/batch on the gateway allowlist (#42572) 2026-09-22 14:09:40 -07:00
provider fix(provider): accept 2xx status codes in unified_access_group create (#42461) 2026-09-28 13:54:37 -07:00