fix(proxy): keep request identifiers named like keys in stored spend-log requests

This commit is contained in:
Yucheng He 2026-09-29 15:10:10 -07:00
parent 2b75e89231
commit 042640688d
2 changed files with 10 additions and 2 deletions

View file

@ -1086,13 +1086,19 @@ def _get_messages_for_spend_logs_payload(
_SENSITIVE_REQUEST_BODY_KEYS: Final = frozenset({"secret_fields"})
_REQUEST_BODY_CREDENTIAL_MASKER: Final = SensitiveDataMasker(extra_sensitive_patterns=frozenset({"apikey"}))
_PROXY_KEY_IDENTITY_FIELDS: Final = frozenset(StandardLoggingUserAPIKeyMetadata.__annotations__) | {"user_api_key"}
_NON_CREDENTIAL_KEY_FIELDS: Final = frozenset(StandardLoggingUserAPIKeyMetadata.__annotations__) | {
"user_api_key",
"prompt_cache_key",
"idempotency_key",
"cache_key",
"preset_cache_key",
}
def _is_request_body_credential(key: str, value: object) -> bool:
return (
isinstance(value, str)
and key not in _PROXY_KEY_IDENTITY_FIELDS
and key not in _NON_CREDENTIAL_KEY_FIELDS
and _REQUEST_BODY_CREDENTIAL_MASKER.is_sensitive_key(key)
)

View file

@ -2756,6 +2756,7 @@ def test_proxy_server_request_payload_redacts_provider_credentials(mock_should_s
"model": "azure-gpt",
"messages": [{"role": "user", "content": "hello"}],
"max_tokens": 10,
"prompt_cache_key": "user-123-cache",
"vertex_credentials": {"private_key": "canary-private-key", "client_email": "sa@example.com"},
"extra_headers": {"Authorization": "Bearer canary-extra-header"},
"tools": [
@ -2781,6 +2782,7 @@ def test_proxy_server_request_payload_redacts_provider_credentials(mock_should_s
assert parsed["tools"][1]["server_url"] == "https://mcp.example.com"
assert parsed["metadata"] == identity_metadata
assert parsed["max_tokens"] == 10
assert parsed["prompt_cache_key"] == "user-123-cache"
assert parsed["messages"] == [{"role": "user", "content": "hello"}]