From 4f97b551c825e164410fdf070c109513983f84ac Mon Sep 17 00:00:00 2001 From: yucheng-berri Date: Tue, 23 Jun 2026 12:16:09 -0700 Subject: [PATCH] test: actually exercise the depth cap in fails-closed test MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous fixture stored the leaf under the secret-named key 'aws_web_identity_token', which the recursor's key-name short-circuit redacts regardless of the cap — so the test passed both with and without the cap in place. Empirically confirmed: under an uncapped mutant the old fixture still hides the secret (key-name catches it), the new fixture leaks it (only the cap can stop it). Swap the leaf key to a non-secret name so the cap is the only redaction path exercised, making the test fail on mutation as advertised. --- .../proxy/proxy_server/test_routes_config.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/tests/test_litellm/proxy/proxy_server/test_routes_config.py b/tests/test_litellm/proxy/proxy_server/test_routes_config.py index 15571d7f1da..df14dc5b5dc 100644 --- a/tests/test_litellm/proxy/proxy_server/test_routes_config.py +++ b/tests/test_litellm/proxy/proxy_server/test_routes_config.py @@ -360,11 +360,11 @@ def test_redact_secret_values_in_obj_fails_closed_at_max_depth(): branch to fail-open would surface here.""" from litellm.proxy import proxy_server as ps - # build a non-secret-keyed wrap chain deeper than the cap, with a real - # secret at the bottom. Using a non-secret key ("wrap") forces the - # recursor down the recursion branch instead of short-circuiting on the - # key name itself. - nested: object = {"aws_web_identity_token": "sk-leak-bottom"} + # leaf and wrap keys are both NON-secret so neither the key-name + # short-circuit nor the explicit-secret set catches the leak. The cap is + # the only thing standing between the secret and the response — flip the + # cap to fail-open and the secret comes back verbatim. + nested: object = {"notes": "sk-leak-bottom"} for _ in range(ps._REDACT_SECRET_MAX_DEPTH + 2): nested = {"wrap": nested}