diff --git a/litellm/proxy/health_endpoints/_health_endpoints.py b/litellm/proxy/health_endpoints/_health_endpoints.py index 9b1fe29471b..0e677a10a5f 100644 --- a/litellm/proxy/health_endpoints/_health_endpoints.py +++ b/litellm/proxy/health_endpoints/_health_endpoints.py @@ -83,6 +83,7 @@ _HEALTH_CREDENTIAL_FIELDS = ( "litellm_credential_name", "aws_secret_access_key", "aws_session_token", + "aws_web_identity_token", "azure_ad_token", "vertex_credentials", ) diff --git a/litellm/proxy/management_endpoints/model_management_endpoints.py b/litellm/proxy/management_endpoints/model_management_endpoints.py index f1eab257253..43601dcf8ad 100644 --- a/litellm/proxy/management_endpoints/model_management_endpoints.py +++ b/litellm/proxy/management_endpoints/model_management_endpoints.py @@ -76,6 +76,7 @@ _CREDENTIAL_LITELLM_PARAMS = ( "litellm_credential_name", "aws_secret_access_key", "aws_session_token", + "aws_web_identity_token", "azure_ad_token", "vertex_credentials", ) diff --git a/tests/test_litellm/proxy/management_endpoints/test_model_management_endpoints.py b/tests/test_litellm/proxy/management_endpoints/test_model_management_endpoints.py index d00d52c26ad..48b2fbff54c 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_model_management_endpoints.py +++ b/tests/test_litellm/proxy/management_endpoints/test_model_management_endpoints.py @@ -2544,3 +2544,17 @@ class TestModelMgmtAuthzHardening: self._assert_resupply( {"sagemaker_base_url": "https://attacker.example"}, db ) + + def test_sts_endpoint_change_requires_web_identity_token_resupply(self): + from litellm.proxy._types import ProxyException + + # Repointing aws_sts_endpoint must require re-supplying a stored web + # identity token; supplying an unrelated credential must not let it ride. + db = { + "aws_sts_endpoint": "https://sts.real", + "aws_web_identity_token": "stored-token", + } + with pytest.raises(ProxyException): + self._assert_resupply( + {"aws_sts_endpoint": "https://sts.attacker", "api_key": "x"}, db + )