mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-09 03:18:44 +00:00
test: actually exercise the depth cap in fails-closed test
The previous fixture stored the leaf under the secret-named key 'aws_web_identity_token', which the recursor's key-name short-circuit redacts regardless of the cap — so the test passed both with and without the cap in place. Empirically confirmed: under an uncapped mutant the old fixture still hides the secret (key-name catches it), the new fixture leaks it (only the cap can stop it). Swap the leaf key to a non-secret name so the cap is the only redaction path exercised, making the test fail on mutation as advertised.
This commit is contained in:
parent
458f086df8
commit
4f97b551c8
1 changed files with 5 additions and 5 deletions
|
|
@ -360,11 +360,11 @@ def test_redact_secret_values_in_obj_fails_closed_at_max_depth():
|
|||
branch to fail-open would surface here."""
|
||||
from litellm.proxy import proxy_server as ps
|
||||
|
||||
# build a non-secret-keyed wrap chain deeper than the cap, with a real
|
||||
# secret at the bottom. Using a non-secret key ("wrap") forces the
|
||||
# recursor down the recursion branch instead of short-circuiting on the
|
||||
# key name itself.
|
||||
nested: object = {"aws_web_identity_token": "sk-leak-bottom"}
|
||||
# leaf and wrap keys are both NON-secret so neither the key-name
|
||||
# short-circuit nor the explicit-secret set catches the leak. The cap is
|
||||
# the only thing standing between the secret and the response — flip the
|
||||
# cap to fail-open and the secret comes back verbatim.
|
||||
nested: object = {"notes": "sk-leak-bottom"}
|
||||
for _ in range(ps._REDACT_SECRET_MAX_DEPTH + 2):
|
||||
nested = {"wrap": nested}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue