From a86ca4152bdfa696d06e89816de15cba9049d4ab Mon Sep 17 00:00:00 2001 From: Kylinny Date: Sun, 27 Sep 2026 11:28:55 -0700 Subject: [PATCH] fix(a2a): forward allowlisted x-litellm-* headers on message/send Allowlisted x-litellm-* headers (e.g. x-litellm-api-key) configured via agent extra_headers are now forwarded to the backend A2A agent. Previously _forwarding_headers() dropped every x-litellm-* header, which silently discarded the allowlisted values. The blanket prefix filter is replaced with an exact, case-insensitive deny-list of proxy-minted identity headers (x-litellm-agent-id, x-litellm-user-id, x-litellm-team-id, x-litellm-trace-id), so forged identity headers still cannot pass through or overwrite the proxy-minted values. Fixes BerriAI/litellm#43450 --- litellm/proxy/agent_endpoints/a2a_endpoints.py | 7 +++++-- .../proxy/agent_endpoints/test_a2a_endpoints.py | 4 ++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/agent_endpoints/a2a_endpoints.py b/litellm/proxy/agent_endpoints/a2a_endpoints.py index 5e5e43e2da2..b63afe536e1 100644 --- a/litellm/proxy/agent_endpoints/a2a_endpoints.py +++ b/litellm/proxy/agent_endpoints/a2a_endpoints.py @@ -174,13 +174,16 @@ async def _resolve_backend_auth_header( # Headers the proxy mints itself on the backend call. Forged client copies of -# these must not be forwarded, but any other x-litellm-* header (e.g. an -# admin-allowlisted x-litellm-api-key from extra_headers) is valid passthrough. +# these must not be forwarded (agent-id is minted later in asend_message, where +# agent_extra_headers would otherwise overwrite it), but any other x-litellm-* +# header (e.g. an admin-allowlisted x-litellm-api-key from extra_headers) is +# valid passthrough. _MINTED_A2A_IDENTITY_HEADERS: Final = frozenset( { AGENT_CALLER_USER_ID_HEADER.lower(), AGENT_CALLER_TEAM_ID_HEADER.lower(), "x-litellm-trace-id", + "x-litellm-agent-id", } ) diff --git a/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py b/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py index ea1143a1d8e..2690bb88401 100644 --- a/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py +++ b/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py @@ -657,6 +657,7 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str mock_request.headers = { "x-litellm-api-key": "sk-allowlisted", "x-a2a-test-agent-x-litellm-team-id": "attacker-team", + "x-a2a-test-agent-x-litellm-agent-id": "attacker-agent", } user_api_key_dict = UserAPIKeyAuth(api_key="sk-test", user_id="real-user", team_id="real-team") @@ -670,6 +671,9 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str assert forwarded_headers.get("X-LiteLLM-Team-Id") == "real-team", ( "proxy-minted team id must not be overridden by a forged client header" ) + assert "x-litellm-agent-id" not in {k.lower() for k in forwarded_headers}, ( + "forged agent id must be stripped before asend_message mints the real one" + ) @pytest.mark.asyncio