fix(a2a): forward allowlisted x-litellm-* headers on message/send

Allowlisted x-litellm-* headers (e.g. x-litellm-api-key) configured via
agent extra_headers are now forwarded to the backend A2A agent.
Previously _forwarding_headers() dropped every x-litellm-* header,
which silently discarded the allowlisted values.

The blanket prefix filter is replaced with an exact, case-insensitive
deny-list of proxy-minted identity headers (x-litellm-agent-id,
x-litellm-user-id, x-litellm-team-id, x-litellm-trace-id), so forged
identity headers still cannot pass through or overwrite the
proxy-minted values.

Fixes BerriAI/litellm#43450
This commit is contained in:
Kylinny 2026-09-27 11:28:55 -07:00
parent 424a677f6f
commit a86ca4152b
2 changed files with 9 additions and 2 deletions

View file

@ -174,13 +174,16 @@ async def _resolve_backend_auth_header(
# Headers the proxy mints itself on the backend call. Forged client copies of
# these must not be forwarded, but any other x-litellm-* header (e.g. an
# admin-allowlisted x-litellm-api-key from extra_headers) is valid passthrough.
# these must not be forwarded (agent-id is minted later in asend_message, where
# agent_extra_headers would otherwise overwrite it), but any other x-litellm-*
# header (e.g. an admin-allowlisted x-litellm-api-key from extra_headers) is
# valid passthrough.
_MINTED_A2A_IDENTITY_HEADERS: Final = frozenset(
{
AGENT_CALLER_USER_ID_HEADER.lower(),
AGENT_CALLER_TEAM_ID_HEADER.lower(),
"x-litellm-trace-id",
"x-litellm-agent-id",
}
)

View file

@ -657,6 +657,7 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str
mock_request.headers = {
"x-litellm-api-key": "sk-allowlisted",
"x-a2a-test-agent-x-litellm-team-id": "attacker-team",
"x-a2a-test-agent-x-litellm-agent-id": "attacker-agent",
}
user_api_key_dict = UserAPIKeyAuth(api_key="sk-test", user_id="real-user", team_id="real-team")
@ -670,6 +671,9 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str
assert forwarded_headers.get("X-LiteLLM-Team-Id") == "real-team", (
"proxy-minted team id must not be overridden by a forged client header"
)
assert "x-litellm-agent-id" not in {k.lower() for k in forwarded_headers}, (
"forged agent id must be stripped before asend_message mints the real one"
)
@pytest.mark.asyncio