fix(key_management): allow /key/update to keep or shrink MCP server grants the key already holds - #38463
Conversation
…rants the key already holds Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
|
|
No action taken on #38463 — it currently has zero labels, so the required |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Greptile SummaryThis PR allows same-team key updates to retain or reduce existing MCP server grants without permitting new grants outside the team allowlist.
Confidence Score: 5/5The PR appears safe to merge. No blocking failure remains; the previously reported redundant object-permission lookup has been removed by reusing the relation included in the existing-key query.
|
| Filename | Overview |
|---|---|
| litellm/proxy/management_endpoints/key_management_endpoints.py | Includes the object-permission relation in the existing-key lookup and passes it to validation only when the team remains unchanged. |
| litellm/proxy/management_helpers/object_permission_utils.py | Resolves grandfathered MCP server identifiers from the supplied relation without repeating the object-permission database lookup. |
| tests/test_litellm/proxy/management_endpoints/test_key_management_endpoints.py | Verifies relation loading and same-team propagation into MCP validation. |
| tests/test_litellm/proxy/management_helpers/test_object_permission_utils.py | Covers retention, shrinking, rejection of new grants, strict validation without an existing permission, tool permissions, and sentinels. |
Reviews (2): Last reviewed commit: "fix(key_management): reuse key row's inc..." | Re-trigger Greptile
…ad of a second lookup Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
@greptileai please re-review: the key update now reuses the included object_permission relation instead of a second database lookup |
TLDR
Problem this solves:
How it solves it:
User Flow
Before: a proxy admin cannot edit a team key whose MCP servers are no longer in the team allowlist
object_permission.mcp_serverslist unchangedAfter: the same admin can keep or shrink those grants, and only genuinely new servers are checked
mcp_serverslist and get 200 with the updated key objectRelevant issues
Linear ticket
Resolves LIT-6062
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)Screenshots / Proof of Fix
Setup shared by both runs: local proxy on http://localhost:4000 backed by Postgres, two DB-registered MCP servers
8931af5f-8628-4058-a6e3-2fa6df234b90(A) and1bc10590-6d87-4375-8dd4-ef92e8cd8a05(B), a teamc92919d0-6551-4525-af2f-6124493751d2whose allowlist was emptied after the key was created, and a team keyrepro-key-6062whose object_permission still holds A and B.$Kis that key,$SA/$SBare the server idsBefore (3b50819)
Re-send the key's own unchanged grants
curl -X POST http://localhost:4000/key/update -H "Authorization: Bearer sk-1234" -H "Content-Type: application/json" -d "{\"key\":\"$K\",\"object_permission\":{\"mcp_servers\":[\"$SA\",\"$SB\"]}}"{"error":{"message":"{'error': \"Key requests MCP servers not allowed by team 'c92919d0-6551-4525-af2f-6124493751d2': ['1bc10590-6d87-4375-8dd4-ef92e8cd8a05', '8931af5f-8628-4058-a6e3-2fa6df234b90']. Team allows: []. Global (allow_all_keys) servers: [].\"}","type":"auth_error","code":"403"}}Shrink to one already-held server
\"mcp_servers\":[\"$SA\"]Control: unrelated edit with no object_permission
{"key":"$K","max_budget":25}and no object_permissionAfter (ede05eb)
Re-send the key's own unchanged grants
curl -X POST http://localhost:4000/key/update -H "Authorization: Bearer sk-1234" -H "Content-Type: application/json" -d "{\"key\":\"$K\",\"object_permission\":{\"mcp_servers\":[\"$SA\",\"$SB\"]}}""key_alias": "repro-key-6062"and the full key objectAdding a genuinely new out-of-team server still fails
0d53fcae-a01e-4b07-81bf-f8b1b6f21675), not held by the key and not in the team allowlist, then same call with\"mcp_servers\":[\"$SA\",\"$SB\",\"$SC\"]Key requests MCP servers not allowed by team 'c92919d0-6551-4525-af2f-6124493751d2': ['0d53fcae-a01e-4b07-81bf-f8b1b6f21675']. Team allows: []. Global (allow_all_keys) servers: [].Shrink to one already-held server
\"mcp_servers\":[\"$SA\"]Type
🐛 Bug Fix
Caveats (if any)
Medium
Low
Final Attestation
Link to Devin session: https://app.devin.ai/sessions/b8fa5b91b8fc4c6a93aef58d1b46fb99
Open in Devin Desktop: https://app.devin.ai/desktop/session/b8fa5b91b8fc4c6a93aef58d1b46fb99?variant=devin
Requested by: @yassin-berriai