Skip to content

fix(auth): deny userless keys with 403 instead of 503 - #3

Merged
tin-berri merged 1 commit into
mainfrom
fix/userless-key-forbidden
Oct 1, 2026
Merged

tin-berri merged 1 commit into
mainfrom
fix/userless-key-forbidden

Conversation

@tin-berri

Copy link
Copy Markdown
Collaborator

Problem

Valid LiteLLM keys with no user row get a retryable 503 from the HTTP connector instead of 403. That covers team keys, keys with no user or team, and service-account keys. LiteLLM's /user/info returns 404 "User None not found" for them, and RequireAdmin maps every status other than 401 or 403 to 503.

Found by a deep gauntlet run on BerriAI/litellm#43881 and reproduced against a real proxy and Postgres.

Fix

Gateway.authorize treats a /user/info 404 as a caller with no user row. It falls through to the existing "Only current LiteLLM proxy admins" 403. Other failures keep their current mapping.

Tests

The stub gateway returns LiteLLM's 404 for a team-key credential. The HTTP transport test asserts that this key gets 403. The assertion fails on main with 503 and passes with the fix. The full suite passes with 87 tests.

🤖 Generated with Claude Code

LiteLLM's /user/info returns 404 for valid keys with no user row (team,
bare and service-account keys). RequireAdmin mapped that to a retryable
503. Treat the 404 as a non-admin caller so it gets 403.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tin-berri
tin-berri merged commit d35ec9c into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant