test(params): fence proxy metadata keys out of provider bodies

The fence test now sends metadata={"user_api_key_hash": "h"} and asserts the key reaches none of the six providers. AGENTS.md now states the _litellm_* naming rule for internal kwargs and that internal state never goes into metadata
This commit is contained in:
shrey kharbanda 2026-09-26 23:20:06 +00:00
parent e494723105
commit f3cf654856
No known key found for this signature in database
2 changed files with 3 additions and 0 deletions

View file

@ -103,6 +103,7 @@ Follow these coding conventions for new/updated code (a three-line fix in a lega
- No monster files or god objects
- No file sprawl: deliberate file and folder structure
- Standard over hand-rolled: use the official SDK or a library where one exists; where none does, follow industry standards instead of inventing local conventions
- Internal kwargs: name any kwarg LiteLLM code adds to a request `_litellm_*`. `is_litellm_owned_kwarg` then keeps it out of every provider body, with no edit to `all_litellm_params`. Never write internal state into `metadata`, since OpenAI also treats it as an API param. Use `litellm_metadata` or a `ContextVar` instead
- API-fragmentation-aware: when logic must branch on which API surface produced or consumes data (e.g. chat completions vs Anthropic Messages vs Responses API shapes), proactively look for an existing shared helper (e.g. `litellm_core_utils/prompt_templates/factory.py`) before writing per-surface parsing in the new module; if none exists, add one there instead of duplicating the same format-detection logic in every new guardrail/integration
Follow conventional commits for commit names and PR titles

View file

@ -290,6 +290,7 @@ async def test_internal_params_never_reach_provider_body(
"stream_chunk_size": 64,
"_litellm_undeclared_sentinel": "internal",
"extra_body": {"custom_provider_key": 1},
"metadata": {"user_api_key_hash": "h"},
"max_tokens": 16,
"timeout": 5,
"num_retries": 0,
@ -310,6 +311,7 @@ async def test_internal_params_never_reach_provider_body(
body: Final = json.loads(requests[0].body)
keys: Final = keys_at_every_depth(body)
assert "stream_chunk_size" not in keys
assert "user_api_key_hash" not in keys, keys
assert not INTERNAL_FIELDS.intersection(keys)
assert not frozenset(key for key in keys if key.startswith("_litellm_")), keys
assert _custom_key(body, provider) == 1