Coverage for .venv/lib/python3.13/site-packages/litellm/proxy/auth/resolvers/models.py: 100%

48 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-10 12:01 +0000

1from __future__ import annotations 

2 

3from enum import Enum 

4 

5from pydantic import BaseModel, ConfigDict, Field 

6 

7from litellm.proxy._types import UserAPIKeyAuth 

8from litellm.proxy.auth.auth_method import AuthMethod 

9from litellm.proxy.auth.network import NetworkContext 

10from litellm.proxy.auth.roles import Role, TeamRole 

11 

12 

13class PrincipalType(str, Enum): 

14 HUMAN = "human" 

15 SERVICE_ACCOUNT = "service_account" 

16 

17 

18class UserIdentity(BaseModel): 

19 id: str 

20 external_id: str | None = None 

21 user_name: str | None = None 

22 email: str | None = None 

23 display_name: str | None = None 

24 

25 

26class OrganizationIdentity(BaseModel): 

27 id: str 

28 name: str | None = None 

29 

30 

31class TeamIdentity(BaseModel): 

32 id: str 

33 name: str | None = None 

34 role: TeamRole = TeamRole.MEMBER 

35 

36 

37class ProjectIdentity(BaseModel): 

38 id: str 

39 name: str | None = None 

40 

41 

42class EndUserIdentity(BaseModel): 

43 id: str 

44 

45 

46class CredentialRef(BaseModel): 

47 key_id: str | None = None 

48 token_id: str | None = None 

49 

50 

51class Principal(BaseModel): 

52 """Normalized caller identity, resolved once per request at the auth seam. 

53 

54 Frozen and constructed fresh per request, never cached or shared. The identity 

55 fields carry no policy, budget, or rate-limit state. ``source_key`` is a 

56 transitional carrier for the resolved key object so ``key_from_principal`` can 

57 hand it to the request flow that still consumes ``UserAPIKeyAuth``; it is 

58 excluded from serialization and repr and goes away once those consumers read 

59 identity off the Principal directly. 

60 """ 

61 

62 model_config = ConfigDict(frozen=True) 

63 

64 principal_type: PrincipalType 

65 subject: str 

66 issuer: str | None = None 

67 audience: list[str] = Field(default_factory=list) 

68 

69 user: UserIdentity | None = None 

70 organization: OrganizationIdentity | None = None 

71 teams: list[TeamIdentity] = Field(default_factory=list) 

72 project: ProjectIdentity | None = None 

73 end_user: EndUserIdentity | None = None 

74 

75 roles: list[Role] = Field(default_factory=list) 

76 scopes: list[str] = Field(default_factory=list) 

77 

78 auth_method: AuthMethod 

79 credential_ref: CredentialRef = Field(default_factory=CredentialRef) 

80 network: NetworkContext = Field(default_factory=NetworkContext) 

81 

82 source_key: UserAPIKeyAuth | None = Field(default=None, exclude=True, repr=False)