mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
fix(batch-rate-limiter): prevent user metadata flag from bypassing model allowlist
The skip_batch_input_file_rate_limiting flag in litellm_metadata is user-controllable for batch requests (request-body metadata lands in litellm_metadata via LITELLM_METADATA_ROUTES). Honoring it unconditionally also skipped _enforce_batch_file_model_access, letting a restricted key submit a JSONL referencing models outside its allowlist. Only honor the metadata-based skip when the key has no model allowlist to enforce. Co-authored-by: Yassin Kortam <yassin@berri.ai>
This commit is contained in:
parent
7afd657c46
commit
b391f772ad
1 changed files with 10 additions and 1 deletions
|
|
@ -151,8 +151,17 @@ class _PROXY_BatchRateLimiter(CustomLogger):
|
|||
if general_settings.get("disable_batch_input_file_rate_limiting") is True:
|
||||
return True
|
||||
|
||||
# Only honor the metadata-based skip when the key has no model
|
||||
# allowlist to enforce. Otherwise a caller could set this flag in
|
||||
# the request body (it lands in ``litellm_metadata`` for batch
|
||||
# routes) and skip ``_enforce_batch_file_model_access``, smuggling
|
||||
# restricted models into the JSONL.
|
||||
litellm_metadata = data.get("litellm_metadata") or {}
|
||||
if litellm_metadata.get("skip_batch_input_file_rate_limiting") is True:
|
||||
if litellm_metadata.get(
|
||||
"skip_batch_input_file_rate_limiting"
|
||||
) is True and not self._key_requires_batch_model_access_check(
|
||||
user_api_key_dict
|
||||
):
|
||||
return True
|
||||
|
||||
batch_model = self._get_batch_routing_model(data)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue