fix(proxy): let llm_api virtual keys read /model_group/info - #38662
ryan-crabbe-berri merged 1 commit into
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
|
|
No action taken on #38662 — repo and author check out ( |
Greptile SummaryThis PR allows
Confidence Score: 5/5The PR appears safe to merge because the new read access remains restricted to models available to the requesting virtual key. The route-category change has a narrow authorization effect, the handler applies existing per-key model filtering, and no credentials or deployment identifiers are added to the response.
|
| Filename | Overview |
|---|---|
| litellm/proxy/_types.py | Extends the virtual-key model-information allowlist with /model_group/info without changing its separate endpoint classification. |
| tests/test_litellm/proxy/auth/test_route_checks.py | Adds focused regression coverage for the new grant and preserves negative coverage for the administrative /v2/model/info route. |
Reviews (1): Last reviewed commit: "fix(proxy): let llm_api virtual keys rea..." | Re-trigger Greptile
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
TLDR
Problem this solves:
How it solves it:
User Flow
Before: someone testing a virtual key in the Playground has no model to pick, so they can't send anything
GET /model_group/infowith that key, returns 403 "Virtual key is not allowed to call this route. Only allowed to call routes: ['llm_api_routes']"After: the same key lists its models and the chat works
gpt-4o-minihere, and picking one lets them chatGET /model_group/infowith that key returns 200 with only the models that key is allowed to callA key still only sees its own models, so this does not widen what anyone can read
Relevant issues
Linear ticket
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)Delays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
Shared setup, run against a live proxy on localhost:4000 started with
litellm --config litellm/proxy/dev_config.yaml --port 4000, minting the same kind of key the UI creates by default:Before (ca0b951)
Listing model groups with the key
curl -s -w "\nHTTP %{http_code}\n" localhost:4000/model_group/info -H "Authorization: Bearer $K"Playground model picker
After (418b820)
Listing model groups with the key
curl -s -w "\nHTTP %{http_code}\n" localhost:4000/model_group/info -H "Authorization: Bearer $K"Playground model picker
gpt-4o-miniwith "Mode: chat" next to "Enter custom model"Real chat call with the same key
curl -s localhost:4000/v1/chat/completions -H "Authorization: Bearer $K" -H "Content-Type: application/json" -d '{"model":"gpt-4o-mini","messages":[{"role":"user","content":"say hi in 3 words"}]}'Type
🐛 Bug Fix
Caveats (if any)
Low
Link to Devin session: https://app.devin.ai/sessions/a043eb6e3a324294a133ffd6bee3362f
Open in Devin Desktop: https://app.devin.ai/desktop/session/a043eb6e3a324294a133ffd6bee3362f?variant=devin
Requested by: @yassin-berriai