mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-30 01:52:18 +00:00
Revert "chore(proxy): SSRF-guard the /health/test_connection destination"
This reverts commit f512075556.
This commit is contained in:
parent
f512075556
commit
5a074cf27b
2 changed files with 0 additions and 42 deletions
|
|
@ -14,7 +14,6 @@ import litellm
|
|||
from litellm._logging import verbose_logger, verbose_proxy_logger
|
||||
from litellm.constants import HEALTH_CHECK_TIMEOUT_SECONDS
|
||||
from litellm.litellm_core_utils.custom_logger_registry import CustomLoggerRegistry
|
||||
from litellm.litellm_core_utils.url_utils import SSRFError, validate_url
|
||||
from litellm.llms.custom_httpx.http_handler import AsyncHTTPHandler
|
||||
from litellm.proxy._types import (
|
||||
AlertType,
|
||||
|
|
@ -122,26 +121,6 @@ def _reject_inherited_credential_redirect(
|
|||
)
|
||||
|
||||
|
||||
def _reject_ssrf_destination(litellm_params: dict) -> None:
|
||||
"""Block a (possibly request-overridden) api_base/base_url that resolves to an
|
||||
internal/metadata target. Gated on litellm.user_url_validation (default True)
|
||||
with user_url_allowed_hosts as the allowlist escape hatch, mirroring the
|
||||
request-time guard so /health/test_connection cannot be used for SSRF."""
|
||||
if not getattr(litellm, "user_url_validation", False):
|
||||
return
|
||||
for url_field in ("api_base", "base_url"):
|
||||
url_value = litellm_params.get(url_field)
|
||||
if not isinstance(url_value, str) or not url_value:
|
||||
continue
|
||||
try:
|
||||
validate_url(url_value)
|
||||
except SSRFError as e:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail={"error": f"{url_field} is rejected by the SSRF guard: {e}"},
|
||||
)
|
||||
|
||||
|
||||
def get_callback_identifier(callback):
|
||||
"""
|
||||
Get the callback identifier string, handling both strings and objects.
|
||||
|
|
@ -1914,8 +1893,6 @@ async def test_model_connection( # noqa: PLR0915
|
|||
config_litellm_params=config_litellm_params,
|
||||
request_litellm_params=request_litellm_params,
|
||||
)
|
||||
# Block SSRF to internal/metadata targets via the (overridden) destination.
|
||||
_reject_ssrf_destination(litellm_params)
|
||||
|
||||
## Auth check — when the deployment was resolved by id, authorize against
|
||||
## its real owner (model_info), not the caller-supplied model_info, so a
|
||||
|
|
|
|||
|
|
@ -1978,22 +1978,3 @@ def test_reject_inherited_credential_redirect_helper():
|
|||
config_litellm_params={"api_key": "sk-x"},
|
||||
request_litellm_params={"model": "gpt-4o"},
|
||||
)
|
||||
|
||||
|
||||
def test_reject_ssrf_destination_helper():
|
||||
import litellm
|
||||
from fastapi import HTTPException
|
||||
|
||||
from litellm.proxy.health_endpoints._health_endpoints import (
|
||||
_reject_ssrf_destination,
|
||||
)
|
||||
|
||||
# Internal/metadata target is rejected when URL validation is on.
|
||||
with patch.object(litellm, "user_url_validation", True):
|
||||
with pytest.raises(HTTPException):
|
||||
_reject_ssrf_destination(
|
||||
{"api_base": "http://169.254.169.254/latest/meta-data/"}
|
||||
)
|
||||
# The opt-out toggle is honored (internal endpoints / Ollama).
|
||||
with patch.object(litellm, "user_url_validation", False):
|
||||
_reject_ssrf_destination({"api_base": "http://127.0.0.1:8080"})
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue