mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-09 03:18:44 +00:00
fix: req changes by greptile
This commit is contained in:
parent
bcb18420c9
commit
da71199c93
2 changed files with 23 additions and 8 deletions
|
|
@ -212,6 +212,15 @@ _STANDARD_LOGGING_METADATA_KEYS: frozenset = frozenset(
|
|||
StandardLoggingMetadata.__annotations__.keys()
|
||||
)
|
||||
|
||||
# Regex matching sensitive x-* headers that must NOT appear in
|
||||
# requester_custom_headers (defense-in-depth — clean_headers() strips most
|
||||
# of these upstream via _SPECIAL_HEADERS_CACHE).
|
||||
_SENSITIVE_X_HEADER_RE = re.compile(
|
||||
r"^(x-litellm-api-key|x-api-key|x-goog-api-key"
|
||||
r"|x-mcp-(auth|servers|access-groups)"
|
||||
r"|x-mcp-.+-(authorization|x-api-key))$"
|
||||
)
|
||||
|
||||
### GLOBAL VARIABLES ###
|
||||
|
||||
# Cache custom pricing keys as frozenset for O(1) lookups instead of looping through 49 keys
|
||||
|
|
@ -4768,18 +4777,13 @@ class StandardLoggingPayloadSetup:
|
|||
if proxy_server_request is not None:
|
||||
_request_headers = proxy_server_request.get("headers", {})
|
||||
if _request_headers and isinstance(_request_headers, dict):
|
||||
_sensitive_x_header = re.compile(
|
||||
r"^(x-litellm-api-key|x-api-key|x-goog-api-key"
|
||||
r"|x-mcp-(auth|servers|access-groups)"
|
||||
r"|x-mcp-.+-(authorization|x-api-key))$"
|
||||
)
|
||||
custom_headers = {
|
||||
k: v
|
||||
for k, v in _request_headers.items()
|
||||
if k.lower().startswith("x-")
|
||||
and v is not None
|
||||
and isinstance(v, str)
|
||||
and not _sensitive_x_header.match(k.lower())
|
||||
and not _SENSITIVE_X_HEADER_RE.match(k.lower())
|
||||
}
|
||||
if custom_headers:
|
||||
clean_metadata["requester_custom_headers"] = custom_headers
|
||||
|
|
|
|||
|
|
@ -545,6 +545,11 @@ async def test_mcp_sensitive_headers_not_in_logging_callback():
|
|||
raw_headers = {
|
||||
"authorization": "Bearer secret-token",
|
||||
"x-litellm-api-key": "sk-secret-key",
|
||||
"x-api-key": "provider-api-key",
|
||||
"x-goog-api-key": "google-api-key",
|
||||
"x-mcp-auth": "legacy-mcp-auth",
|
||||
"x-mcp-servers": "server1,server2",
|
||||
"x-mcp-access-groups": "group1",
|
||||
"x-mcp-github-authorization": "Bearer gh-token",
|
||||
"x-mcp-zapier-x-api-key": "zapier-secret",
|
||||
"x-custom-safe-header": "safe-value",
|
||||
|
|
@ -585,9 +590,15 @@ async def test_mcp_sensitive_headers_not_in_logging_callback():
|
|||
|
||||
# Sensitive headers must NOT appear
|
||||
assert "authorization" not in custom_headers
|
||||
# x-litellm-api-key is stripped by clean_headers (SpecialHeaders)
|
||||
# Auth headers stripped by clean_headers + regex denylist
|
||||
assert "x-litellm-api-key" not in custom_headers
|
||||
# Server-specific MCP auth headers are filtered by regex
|
||||
assert "x-api-key" not in custom_headers
|
||||
assert "x-goog-api-key" not in custom_headers
|
||||
# MCP config headers stripped by clean_headers + regex denylist
|
||||
assert "x-mcp-auth" not in custom_headers
|
||||
assert "x-mcp-servers" not in custom_headers
|
||||
assert "x-mcp-access-groups" not in custom_headers
|
||||
# Server-specific MCP auth headers filtered by regex
|
||||
assert "x-mcp-github-authorization" not in custom_headers
|
||||
assert "x-mcp-zapier-x-api-key" not in custom_headers
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue