From 87f50202c29be489e7a09588feb11f4b0fa0dbac Mon Sep 17 00:00:00 2001 From: yassin Date: Thu, 27 Aug 2026 01:43:24 +0000 Subject: [PATCH] fix: guard cache_hit filter against non-string defaults in direct calls Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../proxy/spend_tracking/spend_management_endpoints.py | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/litellm/proxy/spend_tracking/spend_management_endpoints.py b/litellm/proxy/spend_tracking/spend_management_endpoints.py index 41a4a977d46..4b598b38f48 100644 --- a/litellm/proxy/spend_tracking/spend_management_endpoints.py +++ b/litellm/proxy/spend_tracking/spend_management_endpoints.py @@ -2316,7 +2316,9 @@ async def ui_view_spend_logs( param="sort_order", code=status.HTTP_400_BAD_REQUEST, ) - if cache_hit is not None and cache_hit.lower() not in {"true", "false"}: + # isinstance guard: direct callers (tests) may leave the fastapi.Query default in place + cache_hit_filter: Final = cache_hit.lower() if isinstance(cache_hit, str) else None + if isinstance(cache_hit, str) and cache_hit_filter not in {"true", "false"}: raise ProxyException( message=f"Invalid cache_hit: {cache_hit}. Must be one of: true, false", type="bad_request", @@ -2554,8 +2556,8 @@ async def ui_view_spend_logs( sql_params.append(f"%{like_escaped_session_id}%") p += 1 - if cache_hit is not None: - if cache_hit.lower() == "true": + if cache_hit_filter is not None: + if cache_hit_filter == "true": sql_conditions.append("LOWER(cache_hit) = 'true'") else: sql_conditions.append("(cache_hit IS NULL OR LOWER(cache_hit) <> 'true')")