From 5267c203739b8e9e3f36e34f6b094d000b2f14c2 Mon Sep 17 00:00:00 2001 From: Yucheng He Date: Tue, 29 Sep 2026 15:36:28 -0700 Subject: [PATCH] refactor(proxy): drop the AWS-only snapshot exclusion now that spend-log redaction is name-based --- litellm/proxy/litellm_pre_call_utils.py | 2 -- litellm/types/llms/bedrock.py | 3 -- .../proxy/test_litellm_pre_call_utils.py | 31 ------------------- 3 files changed, 36 deletions(-) diff --git a/litellm/proxy/litellm_pre_call_utils.py b/litellm/proxy/litellm_pre_call_utils.py index 9ab651748df..d48451de6b1 100644 --- a/litellm/proxy/litellm_pre_call_utils.py +++ b/litellm/proxy/litellm_pre_call_utils.py @@ -186,7 +186,6 @@ def _sanitize_for_log(value: object) -> str: from litellm.router import Router from litellm.secret_managers.main import get_secret_bool from litellm.types.llms.anthropic import ANTHROPIC_API_HEADERS -from litellm.types.llms.bedrock import AWS_CREDENTIAL_VALUE_PARAM_KEYS from litellm.types.services import ServiceTypes from litellm.types.utils import ( CustomPricingLiteLLMParams, @@ -1965,7 +1964,6 @@ def refresh_proxy_server_request_body_snapshot( frozenset({"secret_fields", "proxy_server_request", "litellm_logging_obj"}) | _TRANSPORT_ONLY_CREDENTIAL_KEYS | _CALLBACK_CREDENTIAL_KEYS - | AWS_CREDENTIAL_VALUE_PARAM_KEYS ) body: Final = { # mutable-ok: audit JSON serialization requires a dict with shared nested messages k: v for k, v in data.items() if k not in _body_snapshot_exclude diff --git a/litellm/types/llms/bedrock.py b/litellm/types/llms/bedrock.py index 41327c95ce2..e4c41c3ee5b 100644 --- a/litellm/types/llms/bedrock.py +++ b/litellm/types/llms/bedrock.py @@ -1132,9 +1132,6 @@ class AwsAuthParams(BaseModel): AWS_AUTH_PARAM_KEYS: Final[tuple[str, ...]] = tuple(AwsAuthParams.model_fields) -AWS_CREDENTIAL_VALUE_PARAM_KEYS: Final = frozenset( - {"aws_access_key_id", "aws_secret_access_key", "aws_session_token", "aws_web_identity_token"} -) class BedrockCreateBatchRequest(TypedDict, total=False): diff --git a/tests/test_litellm/proxy/test_litellm_pre_call_utils.py b/tests/test_litellm/proxy/test_litellm_pre_call_utils.py index 7c5ce0c6dc3..84266325226 100644 --- a/tests/test_litellm/proxy/test_litellm_pre_call_utils.py +++ b/tests/test_litellm/proxy/test_litellm_pre_call_utils.py @@ -895,37 +895,6 @@ def test_body_snapshot_excludes_team_callback_credentials() -> None: }, proxy_request -@pytest.mark.asyncio -async def test_add_litellm_data_to_request_body_snapshot_excludes_aws_credentials() -> None: - from litellm.proxy.litellm_pre_call_utils import add_litellm_data_to_request - from litellm.types.llms.bedrock import AWS_CREDENTIAL_VALUE_PARAM_KEYS - - aws_credentials: Final = {name: f"canary-{name}" for name in AWS_CREDENTIAL_VALUE_PARAM_KEYS} - data: Final = { - "model": "bedrock-claude", - "messages": [{"role": "user", "content": "hello"}], - "aws_region_name": "us-east-1", - "aws_role_name": "arn:aws:iam::123456789012:role/bedrock", - **aws_credentials, - } - - updated: Final = await add_litellm_data_to_request( - data=data, - request=_make_request_mock("/v1/chat/completions", {"Content-Type": "application/json"}), - user_api_key_dict=UserAPIKeyAuth(api_key="hashed-key", user_id="test-user"), - proxy_config=MagicMock(), - general_settings={}, - version="test-version", - ) - - snapshot_body: Final = updated["proxy_server_request"]["body"] - assert "canary-" not in json.dumps(snapshot_body, default=str) - assert snapshot_body["aws_region_name"] == "us-east-1" - assert snapshot_body["aws_role_name"] == "arn:aws:iam::123456789012:role/bedrock" - assert snapshot_body["messages"] == [{"role": "user", "content": "hello"}] - assert {name: updated[name] for name in AWS_CREDENTIAL_VALUE_PARAM_KEYS} == aws_credentials - - @pytest.mark.asyncio @pytest.mark.parametrize("pre_call_ran", [False, True]) async def test_post_guardrail_snapshot_preserves_logging_only_masking_in_spend_logs(