Moves is_accepted=True from GET /onboarding/get_token to POST /onboarding/claim_token,
so the flag accurately reflects that a password has been set. Both endpoints now reject
already-used links, with get_token rejecting before any user data is returned.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(ci): handle inline table in pyproject.toml for litellm-proxy-extras version check
* fix: bump litellm-proxy-extras to 0.4.50 in pyproject.toml, requirements.txt, and poetry.lock
* fix(tests): set status_code=200 on JWT mocks and pass pii_tokens through data in presidio test
* fix(jwt): support OIDC discovery URLs, handle roles array, improve error hints
Three fixes for Azure AD JWT auth:
1. OIDC discovery URL support - JWT_PUBLIC_KEY_URL can now be set to
.well-known/openid-configuration endpoints. The proxy fetches the
discovery doc, extracts jwks_uri, and caches it.
2. Handle roles claim as array - when team_id_jwt_field points to a list
(e.g. AAD's "roles": ["team1"]), auto-unwrap the first element instead
of crashing with 'unhashable type: list'.
3. Better error hint for dot-notation indexing - when team_id_jwt_field is
set to "roles.0" or "roles[0]", the 401 error now explains to use
"roles" instead and that LiteLLM auto-unwraps lists.
* Add integration demo script for JWT auth fixes (OIDC discovery, array roles, dot-notation hints)
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
* Add demo_servers.py for manual JWT auth testing with mock JWKS/OIDC endpoints
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
* Add demo screenshots for PR comment
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
* Add integration test results with screenshots for PR review
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
* address greptile review feedback (greploop iteration 1)
- fix: add HTTP status code check in _resolve_jwks_url before parsing JSON
- fix: remove misleading bracket-notation hint from debug log (get_nested_value does not support it)
* Update tests/test_litellm/proxy/auth/test_handle_jwt.py
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
* remove demo scripts and assets
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
The test was using setattr() to set module-level attributes (including
proxy_logging_obj = MagicMock()) on the real litellm.proxy.proxy_server
module, but the finally block only had `pass` — no cleanup.
This left proxy_logging_obj as a MagicMock in subsequent tests running
in the same pytest-xdist worker, causing TypeError when log_db_metrics
decorator called asyncio.create_task(proxy_logging_obj.service_logging_obj
.async_service_success_hook(...)) — a MagicMock is not a coroutine.
Fix: save original attribute values before the test and restore them in
the finally block to ensure test isolation.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix: populate identity fields in proxy admin JWT early-return path
When is_proxy_admin is True, the UserAPIKeyAuth early-return now includes
user_id, team_id, team_alias, team_metadata, org_id, and end_user_id
resolved from the JWT. Previously only user_role and parent_otel_span
were set, causing blank Team Name and Internal User in Request Logs UI.
* test: add unit tests for proxy admin JWT identity fields
- Fast-path early return in check_api_key_for_custom_headers_or_pass_through_endpoints
- startswith(tuple) replaces for-loop substring matching (also more correct)
- Pre-compute _PUBLIC_ROUTES and MAPPED_PASS_THROUGH_PREFIXES at module level
- Deduplicate get_request_route call by passing route as parameter
- Cache dict(request.headers) on request.state per-request
- Remove redundant elif branch from get_api_key (handled by later function)
- Fix: isinstance(request.headers, dict) was always False for Starlette Headers,
silently breaking custom header extraction for pass-through endpoints
* fix(oldteams.tsx): show policies when creating
* fix(proxy/_types.py): ensure mcp rest endpoints can be called by virtual key
ensures UI works with virtual key testing mcp endpoints
* refactor: migrate get object permissions table logic to happen in user api key auth - allows functions to trust user api key object they receive has what they need
* fix(rest_endpoints.py): filter for allowed tools based on what key has access to
* fix(mcp_server_manager.py): ensure only allowed MCP's are returned to the user, via rest endpoints
* Warn when budget lookup fails; cache won't populate
- Add _log_budget_lookup_failure helper in auth_checks.py
- Log at WARNING in get_user_object, get_team_object, get_key_object
when DB lookups fail (schema mismatch, etc.)
- Add schema migration hint for prisma/db errors
- Add dry-run test for _log_budget_lookup_failure
* fix: skip budget lookup failure log for expected user-not-found case
Avoid logging 'cache will not be populated' when the user simply doesn't
exist - not caching is correct behavior in that case. Only log for
unexpected errors (schema, DB, etc.) where the message is meaningful.
* Cleanup code for user cli auth, and make sure not to prompt user for team multiple times while polling
* Adding tests
* Cleanup normalize teams some more
* fix(proxy): support slashes in google route params
* fix(proxy): extract google model ids with slashes
* test(proxy): cover google model ids with slashes