fix(mavvrik): guard startup against decryption failure + sanitize 500 error responses

- proxy_server.py: wrap is_mavvrik_setup() in try/except so a ValueError
  from AES decryption failure (e.g. master-key rotation) logs a warning
  and skips the background job instead of crashing startup
- mavvrik_endpoints.py: catch-all 500 handler now returns type(exc).__name__
  instead of str(exc) to prevent Postgres DSNs leaking into API responses

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Praveen Ghuge 2026-05-12 11:29:26 +05:30
parent 9d5b9450d4
commit 28ddef18ee
2 changed files with 14 additions and 2 deletions

View file

@ -7747,7 +7747,15 @@ class ProxyStartupEvent:
is_mavvrik_setup,
)
if await is_mavvrik_setup():
try:
_mavvrik_ready = await is_mavvrik_setup()
except Exception as _e:
verbose_proxy_logger.warning(
"mavvrik: skipping startup — is_mavvrik_setup() failed: %s", _e
)
_mavvrik_ready = False
if _mavvrik_ready:
from litellm.constants import ( # noqa: PLC0415
MAVVRIK_EXPORT_INTERVAL_MINUTES,
MAVVRIK_EXPORT_USAGE_DATA_JOB_NAME,

View file

@ -85,7 +85,11 @@ async def _mavvrik_errors() -> AsyncIterator[None]:
except ValueError as exc:
raise HTTPException(status_code=400, detail={"error": str(exc)}) from exc
except Exception as exc:
raise HTTPException(status_code=500, detail={"error": str(exc)}) from exc
# Use only the exception type name to avoid leaking internal details
# (e.g. Postgres DSNs, hostnames) into API responses.
raise HTTPException(
status_code=500, detail={"error": type(exc).__name__}
) from exc
# ---------------------------------------------------------------------------