mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-30 01:52:18 +00:00
fix(spend): only treat the exact cli-session-<created_by> value as a batch key alias
A managed object row written by an older build can still carry the raw per-login session token, which shares the cli-session- prefix. Matching on the prefix alone would have surfaced that token as a trusted alias and persisted it verbatim in the batch cost spend log, so the alias check now requires the exact per-user value and every other prefixed value keeps going through redaction Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
parent
6b64b98e76
commit
c7938248d2
2 changed files with 16 additions and 3 deletions
|
|
@ -148,11 +148,11 @@ class CheckBatchCost:
|
|||
verbose_proxy_logger.error(f"CheckBatchCost: could not look up user {user_id} for batch {batch_id}: {e}")
|
||||
return {}
|
||||
|
||||
async def _get_key_alias(self, batch_id: str, api_key: str | None) -> str | None:
|
||||
async def _get_key_alias(self, batch_id: str, api_key: str | None, created_by: str | None) -> str | None:
|
||||
"""Resolve the creating virtual key's alias from its hashed token."""
|
||||
if not api_key:
|
||||
return None
|
||||
if api_key.startswith(f"{CLI_SESSION_KEY_PREFIX}-"):
|
||||
if created_by and api_key == f"{CLI_SESSION_KEY_PREFIX}-{created_by}":
|
||||
return api_key
|
||||
try:
|
||||
key_row: prisma_models.LiteLLM_VerificationToken | None = await _token_table(
|
||||
|
|
@ -234,7 +234,7 @@ class CheckBatchCost:
|
|||
**(await self._get_user_info(batch_id, job.created_by)),
|
||||
}
|
||||
|
||||
key_alias = await self._get_key_alias(batch_id, api_key)
|
||||
key_alias = await self._get_key_alias(batch_id, api_key, job.created_by)
|
||||
if key_alias is not None:
|
||||
metadata["user_api_key_alias"] = key_alias
|
||||
team_alias = await self._get_team_alias(team_id)
|
||||
|
|
|
|||
|
|
@ -2634,6 +2634,19 @@ class TestBatchCostAttribution:
|
|||
assert metadata["user_api_key"] == "cli-session-alice"
|
||||
assert metadata["user_api_key_alias"] == "cli-session-alice"
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_raw_cli_session_token_on_a_legacy_batch_row_is_not_treated_as_the_alias(self):
|
||||
"""A batch row written by an older build stores the raw per-login session token, which shares
|
||||
the cli-session- prefix with the alias. Only the exact cli-session-<created_by> value is the
|
||||
alias; anything else stays a secret so redaction hashes it instead of persisting the token."""
|
||||
instance = self._instance(key_row=None)
|
||||
|
||||
metadata = await instance._build_creator_attribution_metadata(
|
||||
self._job(api_key="cli-session-Qm7xJ2kP9sLw4vT1nR8yAa"), "batch-1"
|
||||
)
|
||||
|
||||
assert metadata.get("user_api_key_alias") is None
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_unnamed_key_keeps_the_creating_user_alias(self):
|
||||
"""Regression: a key generated without key_alias resolves to no alias, and the
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue