From c4f6d82a4f617bf6d0e7633e92348e2267638339 Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Mon, 28 Sep 2026 15:30:07 -0700 Subject: [PATCH] fix(logging): read used_client_oauth_token from the proxy-stamped metadata slot On routes that carry proxy metadata in litellm_metadata, metadata is the caller's own body field, and merge_litellm_metadata lets it win. Resolve the flag from litellm_metadata when the proxy stamped it there so a caller cannot set it in the standard logging payload --- litellm/litellm_core_utils/litellm_logging.py | 9 ++++- .../test_litellm_logging.py | 36 +++++++++++++++++++ 2 files changed, 44 insertions(+), 1 deletion(-) diff --git a/litellm/litellm_core_utils/litellm_logging.py b/litellm/litellm_core_utils/litellm_logging.py index 76795d81906..7784addb215 100644 --- a/litellm/litellm_core_utils/litellm_logging.py +++ b/litellm/litellm_core_utils/litellm_logging.py @@ -288,6 +288,13 @@ _STANDARD_LOGGING_METADATA_KEYS: Final[frozenset[str]] = ( ) +def _proxy_stamped_used_client_oauth_token(metadata: object, litellm_params: Mapping[str, object] | None) -> object: + litellm_metadata: Final = litellm_params.get("litellm_metadata") if litellm_params is not None else None + if isinstance(litellm_metadata, Mapping) and "used_client_oauth_token" in litellm_metadata: + return litellm_metadata["used_client_oauth_token"] + return metadata.get("used_client_oauth_token") if isinstance(metadata, Mapping) else None + + def _get_provider_request_id(original_exception: Exception) -> str | None: try: error_response: Final = getattr(original_exception, "response", None) @@ -5786,7 +5793,7 @@ class StandardLoggingPayloadSetup: team_alias=None, team_id=None, used_client_oauth_token=resolve_used_client_oauth_token( - metadata.get("used_client_oauth_token") if isinstance(metadata, dict) else None, + _proxy_stamped_used_client_oauth_token(metadata, litellm_params), custom_llm_provider, ), ) diff --git a/tests/unit/litellm_core_utils/test_litellm_logging.py b/tests/unit/litellm_core_utils/test_litellm_logging.py index 434cfe72664..104cae45595 100644 --- a/tests/unit/litellm_core_utils/test_litellm_logging.py +++ b/tests/unit/litellm_core_utils/test_litellm_logging.py @@ -4891,6 +4891,42 @@ def test_get_standard_logging_object_payload_resolves_used_client_oauth_token_ag assert payload["metadata"]["used_client_oauth_token"] is expected +@pytest.mark.parametrize( + "metadata, litellm_metadata, expected", + [ + ({"used_client_oauth_token": True}, {"used_client_oauth_token": False}, False), + ({"used_client_oauth_token": False}, {"used_client_oauth_token": True}, True), + ({"used_client_oauth_token": True}, {"compression_savings": 1}, True), + ], +) +def test_get_standard_logging_object_payload_takes_used_client_oauth_token_from_the_proxy_stamped_slot( + logging_obj, metadata: dict, litellm_metadata: dict, expected: bool +): + """On routes that carry proxy metadata in `litellm_metadata`, `metadata` is the caller's own body field, + so a caller writing the flag there must not override what the proxy stamped.""" + from datetime import datetime + + from litellm.litellm_core_utils.litellm_logging import get_standard_logging_object_payload + + now = datetime.now() + payload = get_standard_logging_object_payload( + kwargs={ + "model": "claude-sonnet-5", + "messages": [], + "custom_llm_provider": "anthropic", + "litellm_params": {"metadata": metadata, "litellm_metadata": litellm_metadata}, + }, + init_response_obj={}, + start_time=now, + end_time=now, + logging_obj=logging_obj, + status="success", + ) + + assert payload is not None + assert payload["metadata"]["used_client_oauth_token"] is expected + + def test_get_standard_logging_object_payload_carries_matched_access_groups(logging_obj): """Access groups stamped at auth time reach the logging payload, so integrations see what a request billed.""" from datetime import datetime