From d6ad312a4c2a2d14625210a9bd6daceb14940f97 Mon Sep 17 00:00:00 2001 From: Ryan Crabbe Date: Tue, 3 Mar 2026 13:37:11 -0800 Subject: [PATCH] fix(proxy): validate enforced_file_expires_after keys before access Add key validation for enforced_file_expires_after to return a clear 400 error instead of an unhandled KeyError 500. --- .../proxy/openai_files_endpoints/files_endpoints.py | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/litellm/proxy/openai_files_endpoints/files_endpoints.py b/litellm/proxy/openai_files_endpoints/files_endpoints.py index a641fb1c69f..386ab2bf044 100644 --- a/litellm/proxy/openai_files_endpoints/files_endpoints.py +++ b/litellm/proxy/openai_files_endpoints/files_endpoints.py @@ -458,11 +458,22 @@ async def create_file( # noqa: PLR0915 team_metadata = user_api_key_dict.team_metadata or {} enforced_file_expiry = team_metadata.get("enforced_file_expires_after") if enforced_file_expiry is not None: + if "anchor" not in enforced_file_expiry or "seconds" not in enforced_file_expiry: + raise HTTPException( + status_code=400, + detail={ + "error": "enforced_file_expires_after must contain 'anchor' and 'seconds' keys", + }, + ) expires_after = FileExpiresAfter( anchor=enforced_file_expiry["anchor"], seconds=enforced_file_expiry["seconds"], ) + verbose_proxy_logger.info( + "create_file expires_after: %s", expires_after + ) + _create_file_request = CreateFileRequest( file=file_data, purpose=cast(CREATE_FILE_REQUESTS_PURPOSE, purpose),