From 8d7860b077c090336f5b4694aecce0e352355507 Mon Sep 17 00:00:00 2001 From: ishaan-jaff Date: Thu, 1 Feb 2024 16:29:50 -0800 Subject: [PATCH] (fix) handle when users pass Malformed API Key --- litellm/proxy/proxy_server.py | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) diff --git a/litellm/proxy/proxy_server.py b/litellm/proxy/proxy_server.py index 2bd792daf92..7c8e76062ba 100644 --- a/litellm/proxy/proxy_server.py +++ b/litellm/proxy/proxy_server.py @@ -277,14 +277,6 @@ async def user_api_key_auth( else: return UserAPIKeyAuth() - if api_key is None: - raise Exception("No API Key passed in. api_key is None") - if secrets.compare_digest(api_key, ""): - # missing 'Bearer ' prefix - raise Exception( - f"Malformed API Key passed in. Ensure Key has `Bearer ` prefix. Passed in: {passed_in_key}" - ) - route: str = request.url.path if route == "/user/auth": if general_settings.get("allow_user_auth", False) == True: @@ -310,6 +302,12 @@ async def user_api_key_auth( if api_key is None: # only require api key if master key is set raise Exception(f"No api key passed in.") + if secrets.compare_digest(api_key, ""): + # missing 'Bearer ' prefix + raise Exception( + f"Malformed API Key passed in. Ensure Key has `Bearer ` prefix. Passed in: {passed_in_key}" + ) + # note: never string compare api keys, this is vulenerable to a time attack. Use secrets.compare_digest instead is_master_key_valid = secrets.compare_digest(api_key, master_key) if is_master_key_valid: