From cf9b1031a0bb9d30a74b04bca8a87386ff9b00a5 Mon Sep 17 00:00:00 2001 From: Sameer Kankute Date: Mon, 29 Jun 2026 10:58:38 +0530 Subject: [PATCH] address greptile review feedback (greploop iteration 1) - asqav: redact sensitive keys from top-level metadata before writing audit record - bedrock: raise ValueError when checks block contains only unrecognized/empty keys - milvus: always fall back to MILVUS_API_KEY env when config api_key is absent - ui_sso: use UserRepository instead of raw prisma_client.db.litellm_usertable.count() - openrouter: use setdefault("store", False) to preserve explicit caller-set store=True Co-Authored-By: Claude Sonnet 4.6 --- litellm/integrations/asqav/asqav.py | 4 +++- litellm/llms/openrouter/responses/transformation.py | 2 +- .../proxy/guardrails/guardrail_hooks/bedrock_guardrails.py | 6 ++++++ litellm/proxy/management_endpoints/ui_sso.py | 2 +- litellm/rag/ingestion/milvus_ingestion.py | 2 +- 5 files changed, 12 insertions(+), 4 deletions(-) diff --git a/litellm/integrations/asqav/asqav.py b/litellm/integrations/asqav/asqav.py index 4af9a11932d..cbf5c7ea9f3 100644 --- a/litellm/integrations/asqav/asqav.py +++ b/litellm/integrations/asqav/asqav.py @@ -141,7 +141,9 @@ def _extract_loggable( """ model: str = kwargs.get("model", "") messages: Any = kwargs.get("messages") - metadata: Any = dict(kwargs.get("metadata") or kwargs.get("litellm_metadata") or {}) + raw_metadata: Any = dict(kwargs.get("metadata") or kwargs.get("litellm_metadata") or {}) + # Drop sensitive keys from top-level metadata before writing to the audit log + metadata: dict[str, Any] = {k: v for k, v in raw_metadata.items() if k not in _SENSITIVE_KEYS} _merge_proxy_metadata(kwargs, metadata) latency_ms: int | None = None diff --git a/litellm/llms/openrouter/responses/transformation.py b/litellm/llms/openrouter/responses/transformation.py index bdf421b4f61..df716b8fdeb 100644 --- a/litellm/llms/openrouter/responses/transformation.py +++ b/litellm/llms/openrouter/responses/transformation.py @@ -81,7 +81,7 @@ class OpenRouterResponsesAPIConfig(OpenAIResponsesAPIConfig): litellm_params: GenericLiteLLMParams, headers: dict, ) -> dict: - response_api_optional_request_params["store"] = False + response_api_optional_request_params.setdefault("store", False) return super().transform_responses_api_request( model=model, input=input, diff --git a/litellm/proxy/guardrails/guardrail_hooks/bedrock_guardrails.py b/litellm/proxy/guardrails/guardrail_hooks/bedrock_guardrails.py index 43691012aa1..b2fb8a26d0e 100644 --- a/litellm/proxy/guardrails/guardrail_hooks/bedrock_guardrails.py +++ b/litellm/proxy/guardrails/guardrail_hooks/bedrock_guardrails.py @@ -273,6 +273,12 @@ class BedrockGuardrail(CustomGuardrail, BaseAWSLLM): cleaned = { key: value for key, value in checks.items() if key in _BEDROCK_CHECKS_KNOWN_KEYS and value is not None } + if not cleaned and checks: + raise ValueError( + f"BedrockGuardrail: 'checks' block contained only unrecognized or empty keys {sorted(checks.keys())}. " + f"Known keys: {sorted(_BEDROCK_CHECKS_KNOWN_KEYS)}. " + "Fix the guardrail config or remove the 'checks' block to use ApplyGuardrail mode." + ) return cleaned or None def _create_bedrock_input_content_request(self, messages: Optional[List[AllMessageValues]]) -> BedrockRequest: diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index da627bf5fb0..e9fa9d45581 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -2228,7 +2228,7 @@ async def _enforce_free_sso_user_limit( if premium_user: return FREE_SSO_USER_LIMIT = 5 - total_users = await prisma_client.db.litellm_usertable.count() + total_users = await UserRepository(prisma_client).table.count() threshold = FREE_SSO_USER_LIMIT if block_at_limit else FREE_SSO_USER_LIMIT + 1 if total_users is not None and total_users >= threshold: raise ProxyException( diff --git a/litellm/rag/ingestion/milvus_ingestion.py b/litellm/rag/ingestion/milvus_ingestion.py index e5079022168..e3e3e156fa6 100644 --- a/litellm/rag/ingestion/milvus_ingestion.py +++ b/litellm/rag/ingestion/milvus_ingestion.py @@ -94,7 +94,7 @@ class MilvusRAGIngestion(BaseRAGIngestion): self.api_base = self.api_base.rstrip("/") config_api_key = self.vector_store_config.get("api_key") - self.api_key = config_api_key if config_api_base else config_api_key or get_secret_str("MILVUS_API_KEY") + self.api_key = config_api_key or get_secret_str("MILVUS_API_KEY") self.vector_field = self.vector_store_config.get("vector_field", MILVUS_DEFAULT_VECTOR_FIELD) self.text_field = self.vector_store_config.get("text_field", MILVUS_DEFAULT_TEXT_FIELD) self.metric_type = self.vector_store_config.get("metric_type", MILVUS_DEFAULT_METRIC_TYPE)