chore(proxy): treat stored credential-name as an inherited credential in the health connection-test guard

The connection-test endpoint already refuses to forward an inherited inline key to a caller-overridden destination; extend that to a deployment whose credential is stored by reference (litellm_credential_name) so the same destination-override exfiltration path is closed for it too. Matches the credential set used on the model-management write paths.
This commit is contained in:
user 2026-05-31 05:44:05 +00:00
parent 5a074cf27b
commit 9d18c15fb2
No known key found for this signature in database
2 changed files with 10 additions and 0 deletions

View file

@ -80,6 +80,7 @@ def _reject_os_environ_references(params: dict) -> None:
_HEALTH_CREDENTIAL_FIELDS = (
"api_key",
"litellm_credential_name",
"aws_secret_access_key",
"aws_session_token",
"vertex_credentials",

View file

@ -1968,6 +1968,15 @@ def test_reject_inherited_credential_redirect_helper():
config_litellm_params={"api_key": "sk-x", "api_base": "https://real"},
request_litellm_params={"api_base": "https://attacker"},
)
# inherited stored-credential-NAME (no inline api_key) + override -> also rejected
with pytest.raises(HTTPException):
_reject_inherited_credential_redirect(
config_litellm_params={
"litellm_credential_name": "openai-cred",
"api_base": "https://real",
},
request_litellm_params={"api_base": "https://attacker"},
)
# request supplies its own credential -> allowed
_reject_inherited_credential_redirect(
config_litellm_params={"api_key": "sk-x"},