From d7059c6c589ea0a0b3d6724000f0f768a2ecb5c0 Mon Sep 17 00:00:00 2001 From: Ishaan Jaff Date: Wed, 24 Jun 2026 13:03:28 -0700 Subject: [PATCH] fix(ai-gateway): redact upstream URL from auth errors (without_url); forward model to verify --- .../crates/ai-gateway/src/auth/client/python.rs | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/litellm-rust/crates/ai-gateway/src/auth/client/python.rs b/litellm-rust/crates/ai-gateway/src/auth/client/python.rs index 1476020e684..72b99e22b93 100644 --- a/litellm-rust/crates/ai-gateway/src/auth/client/python.rs +++ b/litellm-rust/crates/ai-gateway/src/auth/client/python.rs @@ -47,15 +47,22 @@ impl PythonAuthClient { #[axum::async_trait] impl KeyAuthenticator for PythonAuthClient { - async fn verify(&self, key: &str, route: &str) -> Result { + async fn verify( + &self, + key: &str, + route: &str, + model: Option<&str>, + ) -> Result { let response = self .http .post(&self.verify_url) .header(DATA_PLANE_KEY_HEADER, &self.data_plane_key) - .json(&serde_json::json!({ "api_key": key, "route": route })) + .json(&serde_json::json!({ "api_key": key, "route": route, "model": model })) .send() .await - .map_err(|err| AuthError::Upstream(err.to_string()))?; + // `without_url()` strips the target URL from the error — otherwise the + // internal proxy address would leak into AuthError::Upstream. + .map_err(|err| AuthError::Upstream(format!("network error: {}", err.without_url())))?; let status = response.status(); if status == StatusCode::UNAUTHORIZED {