litellm/ui
Ryan Crabbe ab9c875a00
feat: scope guardrail submissions to team members
Backend:
- list_guardrail_submissions no longer 403s non-admins; it returns only
  submissions whose team_id matches one of the caller's teams (via
  get_user_object.teams). Admins still see all.
- Filtering by a team the caller is not in returns 403.
- Users with no team memberships get an empty list (no DB query).
- get_guardrail_submission applies the same scoping to single-item GETs.

Frontend:
- Remove admin-only bail-out in TeamGuardrailsTab.fetchSubmissions so
  internal users actually load their team's submissions.
- Finish antd migration in guardrails.tsx: drop the last Tremor Button.
- Remove guardrailsList.length === 0 gate on the Test Playground tab;
  the playground already renders a "No guardrails available" inline
  empty state, which is more discoverable than a disabled tab.

Tests:
- Cover non-admin scoped access, empty teams, cross-team filter 403,
  and per-submission GET scoping.
2026-04-04 15:35:25 -07:00
..
litellm-dashboard feat: scope guardrail submissions to team members 2026-04-04 15:35:25 -07:00