mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-04 02:31:27 +00:00
chore(proxy): block database_args from /config/field/info
database_args holds DynamoDBArgs, which includes aws_web_identity_token; a read-only admin could read it through the field-info endpoint. This completes the denylist of secret-bearing general_settings fields (master_key, database_url, alert_to_webhook_url, pass_through_endpoints, database_args).
This commit is contained in:
parent
0bdbf8d7bd
commit
a136e69210
2 changed files with 8 additions and 1 deletions
|
|
@ -14262,6 +14262,7 @@ _SECRET_CONFIG_GENERAL_SETTINGS_FIELDS = {
|
|||
"database_url",
|
||||
"alert_to_webhook_url",
|
||||
"pass_through_endpoints",
|
||||
"database_args", # DynamoDBArgs carries aws_web_identity_token
|
||||
}
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -173,7 +173,13 @@ async def test_pass_through_get_masks_headers_for_non_admin_only():
|
|||
@pytest.mark.asyncio
|
||||
@pytest.mark.parametrize(
|
||||
"field_name",
|
||||
["master_key", "database_url", "alert_to_webhook_url", "pass_through_endpoints"],
|
||||
[
|
||||
"master_key",
|
||||
"database_url",
|
||||
"alert_to_webhook_url",
|
||||
"pass_through_endpoints",
|
||||
"database_args",
|
||||
],
|
||||
)
|
||||
async def test_config_field_info_blocks_secret_fields(field_name):
|
||||
from litellm.proxy.proxy_server import get_config_general_settings
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue