From 48c6138e7195eb30363c113c5f277c1b2f0fb5f1 Mon Sep 17 00:00:00 2001 From: user <70670632+stuxf@users.noreply.github.com> Date: Sat, 30 May 2026 20:33:24 +0000 Subject: [PATCH] chore(proxy): fix CI lint + callbacks test for the masking change Adding a typed user_api_key_dict param to get_config turned it into a typed def, so mypy now checks its body and flagged the pre-existing bare `_email_env_vars = {}`; annotate it. Update test_get_config_callbacks_environment_variables to expect masked credential vars for its non-admin caller (the non-secret host stays plaintext). --- litellm/proxy/proxy_server.py | 2 +- tests/proxy_unit_tests/test_proxy_server.py | 13 +++++++++---- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/litellm/proxy/proxy_server.py b/litellm/proxy/proxy_server.py index 1c2c09303ce..e1493f63025 100644 --- a/litellm/proxy/proxy_server.py +++ b/litellm/proxy/proxy_server.py @@ -14775,7 +14775,7 @@ async def get_config( # noqa: PLR0915 "EMAIL_LOGO_URL", "EMAIL_SUPPORT_CONTACT", ] - _email_env_vars = {} + _email_env_vars: Dict[str, Any] = {} for _var in _email_vars: env_variable = environment_variables.get(_var, None) if env_variable is None: diff --git a/tests/proxy_unit_tests/test_proxy_server.py b/tests/proxy_unit_tests/test_proxy_server.py index 9c08175767d..1a2ca9946df 100644 --- a/tests/proxy_unit_tests/test_proxy_server.py +++ b/tests/proxy_unit_tests/test_proxy_server.py @@ -2788,7 +2788,9 @@ async def test_get_config_callbacks_with_all_types(client_no_auth): async def test_get_config_callbacks_environment_variables(client_no_auth): """ Test that /get/config/callbacks correctly includes environment variables - for each callback type. Values are returned as-is from the config (no decryption). + for each callback type. The caller here is not a full proxy admin, so + credential-bearing variables come back masked while non-secret routing + variables (host, endpoint) are returned as-is. """ from litellm.proxy.proxy_server import ProxyConfig @@ -2830,12 +2832,15 @@ async def test_get_config_callbacks_environment_variables(client_no_auth): assert langfuse_callback["type"] == "success" assert "variables" in langfuse_callback - # Verify langfuse env vars are present (values returned as-is, no decryption) + # Credential-bearing vars are masked for this non-admin caller; the + # non-secret host is returned as-is. langfuse_vars = langfuse_callback["variables"] assert "LANGFUSE_PUBLIC_KEY" in langfuse_vars - assert langfuse_vars["LANGFUSE_PUBLIC_KEY"] == "test-public-key" + assert langfuse_vars["LANGFUSE_PUBLIC_KEY"] != "test-public-key" + assert "*" in langfuse_vars["LANGFUSE_PUBLIC_KEY"] assert "LANGFUSE_SECRET_KEY" in langfuse_vars - assert langfuse_vars["LANGFUSE_SECRET_KEY"] == "test-secret-key" + assert langfuse_vars["LANGFUSE_SECRET_KEY"] != "test-secret-key" + assert "*" in langfuse_vars["LANGFUSE_SECRET_KEY"] assert "LANGFUSE_HOST" in langfuse_vars assert langfuse_vars["LANGFUSE_HOST"] == "https://cloud.langfuse.com"