From 61587b41217bf57ecccbd3b6c08ad82b71301c9b Mon Sep 17 00:00:00 2001 From: Ryan Crabbe Date: Sat, 16 May 2026 15:11:58 -0700 Subject: [PATCH] fix(ui): don't leak freshly-entered model auth secrets to display/console The auth values a user types are still sent in the PATCH request, but: - strip them from the locally-stored litellm_params after save so the read-only LiteLLM Params JSON doesn't render the plaintext key - remove the debug console.log in modelPatchUpdateCall that dumped the full update payload (incl. api_key / vertex_credentials) to the browser console on every model update Backend stores these encrypted and returns them masked on refetch. --- .../src/components/model_info_view.tsx | 10 +++++++++- ui/litellm-dashboard/src/components/networking.tsx | 4 ++-- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/ui/litellm-dashboard/src/components/model_info_view.tsx b/ui/litellm-dashboard/src/components/model_info_view.tsx index a36f19569ef..afa9bc6331a 100644 --- a/ui/litellm-dashboard/src/components/model_info_view.tsx +++ b/ui/litellm-dashboard/src/components/model_info_view.tsx @@ -355,11 +355,19 @@ export default function ModelInfoView({ await modelPatchUpdateCall(accessToken, updateData, modelId); + // The secrets the user just typed were sent in the request and are now + // stored encrypted by the backend. Don't echo their plaintext into local + // display state — the read-only LiteLLM Params JSON would render it. + const displayLitellmParams = { ...updatedLitellmParams }; + for (const key of Object.keys(authFieldUpdates)) { + delete displayLitellmParams[key]; + } + const updatedModelData = { ...localModelData, model_name: values.model_name, litellm_model_name: values.litellm_model_name, - litellm_params: updatedLitellmParams, + litellm_params: displayLitellmParams, model_info: updatedModelInfo, }; diff --git a/ui/litellm-dashboard/src/components/networking.tsx b/ui/litellm-dashboard/src/components/networking.tsx index 756348f4937..6213bcc5a6c 100644 --- a/ui/litellm-dashboard/src/components/networking.tsx +++ b/ui/litellm-dashboard/src/components/networking.tsx @@ -3738,8 +3738,8 @@ export const modelPatchUpdateCall = async ( modelId: string, ) => { try { - console.log("Form Values in modelUpateCall:", formValues); // Log the form values before making the API call - + // Intentionally not logging the payload: it can contain freshly-entered + // provider secrets (api_key, vertex_credentials, AWS creds). const url = proxyBaseUrl ? `${proxyBaseUrl}/model/${modelId}/update` : `/model/${modelId}/update`; const response = await fetch(url, { method: "PATCH",