From cee783d247624aa5bf2e10ec84ff467182900332 Mon Sep 17 00:00:00 2001 From: Mihidum Hettiyahandi <55163074+mihidumh@users.noreply.github.com> Date: Thu, 17 Sep 2026 08:30:34 +1000 Subject: [PATCH] refactor(health): derive the connection-override list next to its only reader Move _CONNECTION_OVERRIDE_REQUEST_PARAMS from auth_utils into _health_endpoints, which is its only consumer. The health module keeps importing _BANNED_REQUEST_BODY_PARAMS exactly as the base does, so the PR adds no new cross-module private import and auth_utils carries no unused global (both flagged by CodeQL on the previous head). --- litellm/proxy/auth/auth_utils.py | 11 ----------- litellm/proxy/health_endpoints/_health_endpoints.py | 12 +++++++++++- .../proxy/health_endpoints/test_health_endpoints.py | 4 ++-- 3 files changed, 13 insertions(+), 14 deletions(-) diff --git a/litellm/proxy/auth/auth_utils.py b/litellm/proxy/auth/auth_utils.py index cbae3bdaa8b..3372145e66c 100644 --- a/litellm/proxy/auth/auth_utils.py +++ b/litellm/proxy/auth/auth_utils.py @@ -371,17 +371,6 @@ _BANNED_REQUEST_BODY_PARAMS: Final[tuple[str, ...]] = ( ) -# The banned params that actually describe a CONNECTION — the tuple above minus -# the custom-pricing fields. Pricing fields are banned from a request body -# because they poison the shared model-cost registry, not because they retarget -# or re-authenticate the outbound call. A caller that needs to reason about -# "did this request bring its own connection?" must use this list; the full -# tuple would treat `input_cost_per_token` as a credential. -_CONNECTION_OVERRIDE_REQUEST_PARAMS: Final[tuple[str, ...]] = tuple( - param for param in _BANNED_REQUEST_BODY_PARAMS if param not in CustomPricingLiteLLMParams.model_fields -) - - def _check_banned_params( body: dict, general_settings: dict, diff --git a/litellm/proxy/health_endpoints/_health_endpoints.py b/litellm/proxy/health_endpoints/_health_endpoints.py index b03af69176e..b7952256962 100644 --- a/litellm/proxy/health_endpoints/_health_endpoints.py +++ b/litellm/proxy/health_endpoints/_health_endpoints.py @@ -40,7 +40,7 @@ from litellm.proxy.auth.auth_checks import ( _resolve_key_models_for_auth_check, # pyright: ignore[reportPrivateUsage] # the auth layer's sentinel resolution, reused so /health scopes exactly like a request ) from litellm.proxy.auth.auth_utils import ( - _CONNECTION_OVERRIDE_REQUEST_PARAMS, # pyright: ignore[reportPrivateUsage] # one canonical list, shared with the request-body check + _BANNED_REQUEST_BODY_PARAMS, # pyright: ignore[reportPrivateUsage] # one canonical list, shared with the request-body check ) from litellm.proxy.auth.model_checks import get_key_models from litellm.proxy.auth.user_api_key_auth import user_api_key_auth @@ -72,6 +72,7 @@ from litellm.router_utils.clientside_credential_handler import ( clientside_credential_keys, ) from litellm.secret_managers.main import get_secret_bool +from litellm.types.utils import CustomPricingLiteLLMParams #### Health ENDPOINTS #### @@ -124,6 +125,15 @@ _CONFIG_CONNECTION_FIELDS: Final[frozenset[str]] = frozenset( ) ) +# The banned request-body params that actually describe a CONNECTION — the +# banned list minus the custom-pricing fields. Pricing fields are banned from a +# request body because they poison the shared model-cost registry, not because +# they retarget or re-authenticate the outbound call, so the full list would +# treat `input_cost_per_token` as a credential. +_CONNECTION_OVERRIDE_REQUEST_PARAMS: Final[tuple[str, ...]] = tuple( + param for param in _BANNED_REQUEST_BODY_PARAMS if param not in CustomPricingLiteLLMParams.model_fields +) + def _request_inherits_config_credentials( config_params: Mapping[str, object], diff --git a/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py b/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py index e330d628ac7..6f8c2022455 100644 --- a/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py +++ b/tests/test_litellm/proxy/health_endpoints/test_health_endpoints.py @@ -3707,7 +3707,7 @@ class TestConfigBaseForHealthCheck: assert "sk-configured" not in str(base) def test_every_custom_pricing_field_is_excluded_from_the_connection_list(self): - from litellm.proxy.auth.auth_utils import _CONNECTION_OVERRIDE_REQUEST_PARAMS + from litellm.proxy.health_endpoints._health_endpoints import _CONNECTION_OVERRIDE_REQUEST_PARAMS from litellm.types.utils import CustomPricingLiteLLMParams connection_params = set(_CONNECTION_OVERRIDE_REQUEST_PARAMS) @@ -3718,7 +3718,7 @@ class TestConfigBaseForHealthCheck: ) def test_connection_list_keeps_the_real_credential_and_endpoint_fields(self): - from litellm.proxy.auth.auth_utils import _CONNECTION_OVERRIDE_REQUEST_PARAMS + from litellm.proxy.health_endpoints._health_endpoints import _CONNECTION_OVERRIDE_REQUEST_PARAMS connection_params = set(_CONNECTION_OVERRIDE_REQUEST_PARAMS) for field in ("api_base", "base_url", "azure_ad_token", "vertex_credentials", "user_config"):