fix(proxy): point the FIPS scrypt rejection log at the admin reset path

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-24 08:20:45 +00:00
parent 0660064397
commit d58958c577
2 changed files with 3 additions and 4 deletions

View file

@ -7097,9 +7097,8 @@ def verify_password(password: str, stored: str) -> bool:
if is_fips_mode():
verbose_proxy_logger.error(
"LITELLM_FIPS_MODE is on and this account still has a scrypt password hash, "
"which is not a FIPS approved primitive. Reset the password "
"(POST /user/password/change, or an admin POST /user/update with a new password) "
"so it is stored as pbkdf2 and the account can sign in"
"which is not a FIPS approved primitive. An admin must set a new password with "
"POST /user/update so it is stored as pbkdf2 and the account can sign in again"
)
return False
try:

View file

@ -72,7 +72,7 @@ class TestVerifyPasswordFormats:
with caplog.at_level(logging.ERROR, logger=verbose_proxy_logger.name):
assert verify_password("legacy-scrypt-pass", stored) is False
assert "scrypt" in caplog.text
assert "/user/password/change" in caplog.text
assert "/user/update" in caplog.text
def test_sha256_fallback_verifies_in_both_modes(self, monkeypatch):
stored = hashlib.sha256(b"oldpass").hexdigest()