mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
🔒 Security: Enable authentication for /metrics endpoint by default
Fixes #24530 - /metrics endpoint exposed multi-tenant PII Changes: - Changed require_auth_for_metrics_endpoint default from False to True - Updated middleware documentation to reflect secure-by-default behavior Breaking Change: ⚠️ This is a breaking change. Users who want unauthenticated /metrics must now explicitly set require_auth_for_metrics_endpoint: false Security Impact: - Prevents unauthorized access to multi-tenant PII - CVSS 7.5 (High) vulnerability - Exposed data: team_alias, user emails, client IPs, user agents
This commit is contained in:
parent
d1df4e838b
commit
668a90e021
2 changed files with 4 additions and 5 deletions
|
|
@ -164,7 +164,7 @@ initialized_langfuse_clients: int = 0
|
|||
langfuse_default_tags: Optional[List[str]] = None
|
||||
langsmith_batch_size: Optional[int] = None
|
||||
prometheus_initialize_budget_metrics: Optional[bool] = False
|
||||
require_auth_for_metrics_endpoint: Optional[bool] = False
|
||||
require_auth_for_metrics_endpoint: Optional[bool] = True # Security: Require auth by default (fixes #24530)
|
||||
argilla_batch_size: Optional[int] = None
|
||||
datadog_use_v1: Optional[bool] = False # if you want to use v1 datadog logged payload.
|
||||
gcs_pub_sub_use_v1: Optional[
|
||||
|
|
|
|||
|
|
@ -18,13 +18,12 @@ class PrometheusAuthMiddleware:
|
|||
"""
|
||||
Middleware to authenticate requests to the metrics endpoint.
|
||||
|
||||
By default, auth is not run on the metrics endpoint.
|
||||
|
||||
Enabled by setting the following in proxy_config.yaml:
|
||||
By default, auth IS RUN on the metrics endpoint (secure by default).
|
||||
|
||||
To disable auth (not recommended for production):
|
||||
```yaml
|
||||
litellm_settings:
|
||||
require_auth_for_metrics_endpoint: true
|
||||
require_auth_for_metrics_endpoint: false
|
||||
```
|
||||
"""
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue