refactor(health): derive the connection-override list next to its only reader

Move _CONNECTION_OVERRIDE_REQUEST_PARAMS from auth_utils into
_health_endpoints, which is its only consumer. The health module keeps
importing _BANNED_REQUEST_BODY_PARAMS exactly as the base does, so the PR
adds no new cross-module private import and auth_utils carries no unused
global (both flagged by CodeQL on the previous head).
This commit is contained in:
Mihidum Hettiyahandi 2026-09-17 08:30:34 +10:00
parent fa4a28eca0
commit cee783d247
3 changed files with 13 additions and 14 deletions

View file

@ -371,17 +371,6 @@ _BANNED_REQUEST_BODY_PARAMS: Final[tuple[str, ...]] = (
)
# The banned params that actually describe a CONNECTION — the tuple above minus
# the custom-pricing fields. Pricing fields are banned from a request body
# because they poison the shared model-cost registry, not because they retarget
# or re-authenticate the outbound call. A caller that needs to reason about
# "did this request bring its own connection?" must use this list; the full
# tuple would treat `input_cost_per_token` as a credential.
_CONNECTION_OVERRIDE_REQUEST_PARAMS: Final[tuple[str, ...]] = tuple(
param for param in _BANNED_REQUEST_BODY_PARAMS if param not in CustomPricingLiteLLMParams.model_fields
)
def _check_banned_params(
body: dict,
general_settings: dict,

View file

@ -40,7 +40,7 @@ from litellm.proxy.auth.auth_checks import (
_resolve_key_models_for_auth_check, # pyright: ignore[reportPrivateUsage] # the auth layer's sentinel resolution, reused so /health scopes exactly like a request
)
from litellm.proxy.auth.auth_utils import (
_CONNECTION_OVERRIDE_REQUEST_PARAMS, # pyright: ignore[reportPrivateUsage] # one canonical list, shared with the request-body check
_BANNED_REQUEST_BODY_PARAMS, # pyright: ignore[reportPrivateUsage] # one canonical list, shared with the request-body check
)
from litellm.proxy.auth.model_checks import get_key_models
from litellm.proxy.auth.user_api_key_auth import user_api_key_auth
@ -72,6 +72,7 @@ from litellm.router_utils.clientside_credential_handler import (
clientside_credential_keys,
)
from litellm.secret_managers.main import get_secret_bool
from litellm.types.utils import CustomPricingLiteLLMParams
#### Health ENDPOINTS ####
@ -124,6 +125,15 @@ _CONFIG_CONNECTION_FIELDS: Final[frozenset[str]] = frozenset(
)
)
# The banned request-body params that actually describe a CONNECTION — the
# banned list minus the custom-pricing fields. Pricing fields are banned from a
# request body because they poison the shared model-cost registry, not because
# they retarget or re-authenticate the outbound call, so the full list would
# treat `input_cost_per_token` as a credential.
_CONNECTION_OVERRIDE_REQUEST_PARAMS: Final[tuple[str, ...]] = tuple(
param for param in _BANNED_REQUEST_BODY_PARAMS if param not in CustomPricingLiteLLMParams.model_fields
)
def _request_inherits_config_credentials(
config_params: Mapping[str, object],

View file

@ -3707,7 +3707,7 @@ class TestConfigBaseForHealthCheck:
assert "sk-configured" not in str(base)
def test_every_custom_pricing_field_is_excluded_from_the_connection_list(self):
from litellm.proxy.auth.auth_utils import _CONNECTION_OVERRIDE_REQUEST_PARAMS
from litellm.proxy.health_endpoints._health_endpoints import _CONNECTION_OVERRIDE_REQUEST_PARAMS
from litellm.types.utils import CustomPricingLiteLLMParams
connection_params = set(_CONNECTION_OVERRIDE_REQUEST_PARAMS)
@ -3718,7 +3718,7 @@ class TestConfigBaseForHealthCheck:
)
def test_connection_list_keeps_the_real_credential_and_endpoint_fields(self):
from litellm.proxy.auth.auth_utils import _CONNECTION_OVERRIDE_REQUEST_PARAMS
from litellm.proxy.health_endpoints._health_endpoints import _CONNECTION_OVERRIDE_REQUEST_PARAMS
connection_params = set(_CONNECTION_OVERRIDE_REQUEST_PARAMS)
for field in ("api_base", "base_url", "azure_ad_token", "vertex_credentials", "user_config"):