From 9d18c15fb25a571c85c90602d63e4d0de24efc05 Mon Sep 17 00:00:00 2001 From: user <70670632+stuxf@users.noreply.github.com> Date: Sun, 31 May 2026 05:44:05 +0000 Subject: [PATCH] chore(proxy): treat stored credential-name as an inherited credential in the health connection-test guard The connection-test endpoint already refuses to forward an inherited inline key to a caller-overridden destination; extend that to a deployment whose credential is stored by reference (litellm_credential_name) so the same destination-override exfiltration path is closed for it too. Matches the credential set used on the model-management write paths. --- litellm/proxy/health_endpoints/_health_endpoints.py | 1 + .../proxy/health_endpoints/test_health_endpoints.py | 9 +++++++++ 2 files changed, 10 insertions(+) diff --git a/litellm/proxy/health_endpoints/_health_endpoints.py b/litellm/proxy/health_endpoints/_health_endpoints.py index b6210cf7276..2b9a4b07581 100644 --- a/litellm/proxy/health_endpoints/_health_endpoints.py +++ b/litellm/proxy/health_endpoints/_health_endpoints.py @@ -80,6 +80,7 @@ def _reject_os_environ_references(params: dict) -> None: _HEALTH_CREDENTIAL_FIELDS = ( "api_key", + "litellm_credential_name", "aws_secret_access_key", "aws_session_token", "vertex_credentials", diff --git a/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py b/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py index 58431ad5994..69189522f68 100644 --- a/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py +++ b/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py @@ -1968,6 +1968,15 @@ def test_reject_inherited_credential_redirect_helper(): config_litellm_params={"api_key": "sk-x", "api_base": "https://real"}, request_litellm_params={"api_base": "https://attacker"}, ) + # inherited stored-credential-NAME (no inline api_key) + override -> also rejected + with pytest.raises(HTTPException): + _reject_inherited_credential_redirect( + config_litellm_params={ + "litellm_credential_name": "openai-cred", + "api_base": "https://real", + }, + request_litellm_params={"api_base": "https://attacker"}, + ) # request supplies its own credential -> allowed _reject_inherited_credential_redirect( config_litellm_params={"api_key": "sk-x"},