diff --git a/litellm/types/guardrails.py b/litellm/types/guardrails.py index 02dee40f2a3..81ac515b54d 100644 --- a/litellm/types/guardrails.py +++ b/litellm/types/guardrails.py @@ -1215,6 +1215,8 @@ class ApplyGuardrailResponse(BaseModel): class PatchGuardrailRequest(BaseModel): + model_config = ConfigDict(extra="forbid") + guardrail_name: str | None = None litellm_params: BaseLitellmParams | None = None guardrail_info: dict[str, Any] | None = None diff --git a/tests/test_litellm/proxy/guardrails/test_guardrail_endpoints.py b/tests/test_litellm/proxy/guardrails/test_guardrail_endpoints.py index 530f8ffd854..5cd4f747449 100644 --- a/tests/test_litellm/proxy/guardrails/test_guardrail_endpoints.py +++ b/tests/test_litellm/proxy/guardrails/test_guardrail_endpoints.py @@ -80,6 +80,21 @@ MOCK_PATCH_REQUEST = PatchGuardrailRequest( ) +def test_patch_guardrail_request_rejects_create_body_shape(): + """Do not silently accept the nested POST /guardrails request body.""" + from pydantic import ValidationError + + with pytest.raises(ValidationError, match="extra_forbidden"): + PatchGuardrailRequest.model_validate( + { + "guardrail": { + "guardrail_name": "nested-name", + "litellm_params": {}, + } + } + ) + + @pytest.fixture def mock_prisma_client(mocker): """Mock Prisma client for testing"""