From 903ade4a1b3d10c83c2b7b91ffdc22322739e55e Mon Sep 17 00:00:00 2001 From: Ryan Crabbe Date: Tue, 3 Mar 2026 13:51:41 -0800 Subject: [PATCH] fix(proxy): add anchor validation for file expiry, key validation for batch expiry Validate anchor is "created_at" in enforced_file_expires_after (matching user-provided path). Add key existence validation to batch endpoint for enforced_batch_output_expires_after. --- litellm/proxy/batches_endpoints/endpoints.py | 7 +++++++ litellm/proxy/openai_files_endpoints/files_endpoints.py | 9 ++++++++- 2 files changed, 15 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/batches_endpoints/endpoints.py b/litellm/proxy/batches_endpoints/endpoints.py index 60905243369..850134b649c 100644 --- a/litellm/proxy/batches_endpoints/endpoints.py +++ b/litellm/proxy/batches_endpoints/endpoints.py @@ -125,6 +125,13 @@ async def create_batch( # noqa: PLR0915 "enforced_batch_output_expires_after" ) if enforced_batch_expiry is not None: + if "anchor" not in enforced_batch_expiry or "seconds" not in enforced_batch_expiry: + raise HTTPException( + status_code=400, + detail={ + "error": "enforced_batch_output_expires_after must contain 'anchor' and 'seconds' keys", + }, + ) _create_batch_data["output_expires_after"] = enforced_batch_expiry input_file_id = _create_batch_data.get("input_file_id", None) diff --git a/litellm/proxy/openai_files_endpoints/files_endpoints.py b/litellm/proxy/openai_files_endpoints/files_endpoints.py index 386ab2bf044..82cae8c64ea 100644 --- a/litellm/proxy/openai_files_endpoints/files_endpoints.py +++ b/litellm/proxy/openai_files_endpoints/files_endpoints.py @@ -465,8 +465,15 @@ async def create_file( # noqa: PLR0915 "error": "enforced_file_expires_after must contain 'anchor' and 'seconds' keys", }, ) + if enforced_file_expiry["anchor"] != "created_at": + raise HTTPException( + status_code=400, + detail={ + "error": f"enforced_file_expires_after anchor must be 'created_at', got '{enforced_file_expiry['anchor']}'", + }, + ) expires_after = FileExpiresAfter( - anchor=enforced_file_expiry["anchor"], + anchor="created_at", seconds=enforced_file_expiry["seconds"], )