mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
🔒 Security: Fix incomplete PII removal and stale docstrings
- Fix P1: Remove PII labels from litellm_proxy_failed_requests_metric - Removed TEAM_ALIAS, USER_EMAIL, CLIENT_IP, USER_AGENT - Matches changes in litellm_proxy_total_requests_metric - Prevents PII leak when auth is disabled - Fix P2: Update _mount_metrics_endpoint docstring - Removed reference to non-existent require_auth parameter - Clarified authentication is enabled by default - Fix P2: Update debug log message - Now shows authentication status correctly - Only shown in debug mode Addresses Greptile AI review findings in PR #24895
This commit is contained in:
parent
d3d31dea85
commit
d1a4b488f2
2 changed files with 18 additions and 11 deletions
|
|
@ -3418,11 +3418,10 @@ class PrometheusLogger(CustomLogger):
|
|||
@staticmethod
|
||||
def _mount_metrics_endpoint():
|
||||
"""
|
||||
Mount the Prometheus metrics endpoint with optional authentication.
|
||||
Mount the Prometheus metrics endpoint with authentication.
|
||||
|
||||
Args:
|
||||
require_auth (bool, optional): Whether to require authentication for the metrics endpoint.
|
||||
Defaults to False.
|
||||
Authentication is enabled by default (require_auth_for_metrics_endpoint: True).
|
||||
Set 'require_auth_for_metrics_endpoint: false' in litellm_settings to disable.
|
||||
"""
|
||||
from prometheus_client import make_asgi_app
|
||||
|
||||
|
|
@ -3449,9 +3448,16 @@ class PrometheusLogger(CustomLogger):
|
|||
|
||||
# Mount the metrics app to the app
|
||||
app.mount("/metrics", metrics_app)
|
||||
verbose_proxy_logger.debug(
|
||||
"Starting Prometheus Metrics on /metrics (no authentication)"
|
||||
)
|
||||
|
||||
# Log based on authentication status
|
||||
if litellm.require_auth_for_metrics_endpoint:
|
||||
verbose_proxy_logger.debug(
|
||||
"Starting Prometheus Metrics on /metrics (authentication required)"
|
||||
)
|
||||
else:
|
||||
verbose_proxy_logger.debug(
|
||||
"Starting Prometheus Metrics on /metrics (authentication disabled)"
|
||||
)
|
||||
|
||||
|
||||
def prometheus_label_factory(
|
||||
|
|
|
|||
|
|
@ -351,14 +351,15 @@ class PrometheusMetricLabels:
|
|||
UserAPIKeyLabelNames.API_KEY_ALIAS.value,
|
||||
UserAPIKeyLabelNames.REQUESTED_MODEL.value,
|
||||
UserAPIKeyLabelNames.TEAM.value,
|
||||
UserAPIKeyLabelNames.TEAM_ALIAS.value,
|
||||
# Security: Removed PII labels (fixes #24530)
|
||||
# UserAPIKeyLabelNames.TEAM_ALIAS.value, # Contains company names and employee emails
|
||||
UserAPIKeyLabelNames.USER.value,
|
||||
UserAPIKeyLabelNames.USER_EMAIL.value,
|
||||
# UserAPIKeyLabelNames.USER_EMAIL.value, # Contains email addresses
|
||||
UserAPIKeyLabelNames.EXCEPTION_STATUS.value,
|
||||
UserAPIKeyLabelNames.EXCEPTION_CLASS.value,
|
||||
UserAPIKeyLabelNames.ROUTE.value,
|
||||
UserAPIKeyLabelNames.CLIENT_IP.value,
|
||||
UserAPIKeyLabelNames.USER_AGENT.value,
|
||||
# UserAPIKeyLabelNames.CLIENT_IP.value, # Contains client IP addresses
|
||||
# UserAPIKeyLabelNames.USER_AGENT.value, # Contains workflow IDs and infrastructure info
|
||||
UserAPIKeyLabelNames.MODEL_ID.value,
|
||||
]
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue