chore(proxy): treat aws_web_identity_token as a stored credential in the destination-change guards

aws_sts_endpoint was guarded as a destination, but aws_web_identity_token was not in the credential set, so repointing the STS endpoint while supplying an unrelated credential left a stored web identity token riding along to the attacker's AssumeRoleWithWebIdentity call. Added it to both _CREDENTIAL_LITELLM_PARAMS and _HEALTH_CREDENTIAL_FIELDS, with a regression test that repointing aws_sts_endpoint without re-supplying the token is rejected.
This commit is contained in:
user 2026-05-31 09:42:54 +00:00
parent debc2cf057
commit 5e57f966dc
No known key found for this signature in database
3 changed files with 16 additions and 0 deletions

View file

@ -83,6 +83,7 @@ _HEALTH_CREDENTIAL_FIELDS = (
"litellm_credential_name",
"aws_secret_access_key",
"aws_session_token",
"aws_web_identity_token",
"azure_ad_token",
"vertex_credentials",
)

View file

@ -76,6 +76,7 @@ _CREDENTIAL_LITELLM_PARAMS = (
"litellm_credential_name",
"aws_secret_access_key",
"aws_session_token",
"aws_web_identity_token",
"azure_ad_token",
"vertex_credentials",
)

View file

@ -2544,3 +2544,17 @@ class TestModelMgmtAuthzHardening:
self._assert_resupply(
{"sagemaker_base_url": "https://attacker.example"}, db
)
def test_sts_endpoint_change_requires_web_identity_token_resupply(self):
from litellm.proxy._types import ProxyException
# Repointing aws_sts_endpoint must require re-supplying a stored web
# identity token; supplying an unrelated credential must not let it ride.
db = {
"aws_sts_endpoint": "https://sts.real",
"aws_web_identity_token": "stored-token",
}
with pytest.raises(ProxyException):
self._assert_resupply(
{"aws_sts_endpoint": "https://sts.attacker", "api_key": "x"}, db
)