refactor(proxy): assert separate login counter stores in the spray regression test instead of a comment

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-13 09:18:39 +00:00
parent 05fe17e027
commit 685c654298
2 changed files with 3 additions and 3 deletions

View file

@ -55,8 +55,6 @@ def _bounded_store(max_entries: int) -> DualCache:
)
# Separate stores: eviction is earliest-expiring-first, so in one shared store a spray of
# fresh usernames would evict the source counter that is meant to stop that same spray.
_FAILED_LOGIN_USERNAME_CACHE: Final = _bounded_store(_MAX_TRACKED_LOGIN_USERNAMES)
_FAILED_LOGIN_SOURCE_CACHE: Final = _bounded_store(_MAX_TRACKED_LOGIN_SOURCES)
_NO_SETTINGS: Final = MappingProxyType({})

View file

@ -1472,7 +1472,8 @@ async def test_a_username_spray_cannot_evict_an_existing_counter(monkeypatch):
The default in-memory cache keeps 200 entries and evicts the soonest to expire, and
every counter shares one window, so eviction was effectively oldest-first. A few
hundred made-up usernames therefore pushed out the attacker's own counter and handed
back a fresh allowance against the real account.
back a fresh allowance against the real account. Username and source counters must also
live in separate stores, or the same spray evicts the source counter meant to stop it.
"""
from litellm.proxy._types import ProxyException
from litellm.proxy.auth.login_throttle import (
@ -1489,6 +1490,7 @@ async def test_a_username_spray_cannot_evict_an_existing_counter(monkeypatch):
assert _MAX_TRACKED_LOGIN_USERNAMES >= 10_000
assert _FAILED_LOGIN_SOURCE_CACHE.in_memory_cache.max_size_in_memory == _MAX_TRACKED_LOGIN_SOURCES
assert _FAILED_LOGIN_USERNAME_CACHE.in_memory_cache.max_size_in_memory == _MAX_TRACKED_LOGIN_USERNAMES
assert _FAILED_LOGIN_SOURCE_CACHE.in_memory_cache is not _FAILED_LOGIN_USERNAME_CACHE.in_memory_cache
throttle = LoginThrottle(
client_ip="10.9.9.9",