From 5d36f155b65e72869684d5980ed29e9f1bba7c1f Mon Sep 17 00:00:00 2001 From: jibanez-staticduo Date: Fri, 18 Sep 2026 14:50:16 +0200 Subject: [PATCH] fix: suppress intentional ownership hash alerts --- litellm/proxy/_types.py | 1 + litellm/proxy/realtime_endpoints/call_sessions.py | 2 ++ litellm/proxy/realtime_endpoints/live.py | 1 + litellm/proxy/utils.py | 2 ++ 4 files changed, 6 insertions(+) diff --git a/litellm/proxy/_types.py b/litellm/proxy/_types.py index 741128b2769..f9045d20765 100644 --- a/litellm/proxy/_types.py +++ b/litellm/proxy/_types.py @@ -265,6 +265,7 @@ def hash_token(token: str): import hashlib # This digest is an opaque lookup identifier, not a password hash. + # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token diff --git a/litellm/proxy/realtime_endpoints/call_sessions.py b/litellm/proxy/realtime_endpoints/call_sessions.py index cf4937f3252..803c0998e5e 100644 --- a/litellm/proxy/realtime_endpoints/call_sessions.py +++ b/litellm/proxy/realtime_endpoints/call_sessions.py @@ -220,6 +220,7 @@ def decode_call(token: str, authorization: str) -> CodexRealtimeCall: raise HTTPException(403, "Invalid realtime call") from exc if ( call.expires_at < time.time() + # codeql[py/weak-sensitive-data-hashing] or call.owner != hashlib.sha256(authorization.encode(), usedforsecurity=False).hexdigest() ): raise HTTPException(403, "Invalid or expired realtime call") @@ -400,6 +401,7 @@ async def _create_codex_realtime_call(request: Request) -> Response: call: Final = parse_call_response( response, alias=model, + # codeql[py/weak-sensitive-data-hashing] owner=hashlib.sha256( f"Bearer {owner_key}".encode(), usedforsecurity=False ).hexdigest(), diff --git a/litellm/proxy/realtime_endpoints/live.py b/litellm/proxy/realtime_endpoints/live.py index 8f68e870497..634425c029c 100644 --- a/litellm/proxy/realtime_endpoints/live.py +++ b/litellm/proxy/realtime_endpoints/live.py @@ -185,6 +185,7 @@ def rewrite_session_ids(value: JsonValue | Mapping[str, JsonValue], raw_id: str, def _owner(auth: UserAPIKeyAuth) -> str: if not auth.api_key: raise HTTPException(403, "Live sessions require an authenticated API key") + # codeql[py/weak-sensitive-data-hashing] return hashlib.sha256(auth.api_key.encode(), usedforsecurity=False).hexdigest() diff --git a/litellm/proxy/utils.py b/litellm/proxy/utils.py index dc0ba6bfbd1..6f4ef72f3cf 100644 --- a/litellm/proxy/utils.py +++ b/litellm/proxy/utils.py @@ -4291,6 +4291,7 @@ class PrismaClient: def hash_token(self, token: str): # Hash the string using SHA-256 + # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token @@ -6718,6 +6719,7 @@ def hash_token(token: str): import hashlib # Hash the string using SHA-256 + # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token