fix(ui): don't leak freshly-entered model auth secrets to display/console

The auth values a user types are still sent in the PATCH request, but:
- strip them from the locally-stored litellm_params after save so the
  read-only LiteLLM Params JSON doesn't render the plaintext key
- remove the debug console.log in modelPatchUpdateCall that dumped the
  full update payload (incl. api_key / vertex_credentials) to the browser
  console on every model update

Backend stores these encrypted and returns them masked on refetch.
This commit is contained in:
Ryan Crabbe 2026-05-16 15:11:58 -07:00
parent 2ff503f606
commit 61587b4121
No known key found for this signature in database
2 changed files with 11 additions and 3 deletions

View file

@ -355,11 +355,19 @@ export default function ModelInfoView({
await modelPatchUpdateCall(accessToken, updateData, modelId);
// The secrets the user just typed were sent in the request and are now
// stored encrypted by the backend. Don't echo their plaintext into local
// display state — the read-only LiteLLM Params JSON would render it.
const displayLitellmParams = { ...updatedLitellmParams };
for (const key of Object.keys(authFieldUpdates)) {
delete displayLitellmParams[key];
}
const updatedModelData = {
...localModelData,
model_name: values.model_name,
litellm_model_name: values.litellm_model_name,
litellm_params: updatedLitellmParams,
litellm_params: displayLitellmParams,
model_info: updatedModelInfo,
};

View file

@ -3738,8 +3738,8 @@ export const modelPatchUpdateCall = async (
modelId: string,
) => {
try {
console.log("Form Values in modelUpateCall:", formValues); // Log the form values before making the API call
// Intentionally not logging the payload: it can contain freshly-entered
// provider secrets (api_key, vertex_credentials, AWS creds).
const url = proxyBaseUrl ? `${proxyBaseUrl}/model/${modelId}/update` : `/model/${modelId}/update`;
const response = await fetch(url, {
method: "PATCH",