ryan
1d50d1ad3b
fix(proxy): rewrite every model allowlist in one statement on rename
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:40:59 +00:00
yassin
82ead97961
fix(proxy): resolve pass-through log dispatch lazily so instance patches still apply
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:39:59 +00:00
mateo-berri
99b83a2d52
fix(fireworks_ai): restore supports_vision on minimax-m3 in the cost map
2026-09-17 16:39:31 -07:00
mateo-berri
8e3742a5f3
fix(proxy): answer 503 temporarily_unavailable when the token exchange cannot verify the subject token
...
LiteLLM Rust / rust-lint (push) Waiting to run
LiteLLM Rust / rust-test (push) Waiting to run
LiteLLM Rust / rust-wheel (push) Waiting to run
A subject token JWT auth could not check, because the IdP's JWKS was unreachable with no cached copy or the auth database was down, came back as 400 invalid_request with the same fixed message a bad token gets, so clients re-logged in instead of retrying the way they already do for a mint-time 503. Those checks now answer 503 temporarily_unavailable and log the reason, while real rejections stay 400 invalid_request.
2026-09-17 16:39:02 -07:00
mateo-berri
42f2978061
Merge remote-tracking branch 'origin/main' into HEAD
2026-09-17 16:38:54 -07:00
mateo-berri
1e7e5b695f
fix(router): reject a blank Jev api_key so it cannot pair with a caller-chosen api_base
2026-09-17 16:38:54 -07:00
Mateo Wang
deb9d8aedd
Merge pull request #41607 from BerriAI/litellm_typesafe_passthrough
...
LiteLLM Rust / rust-test (push) Waiting to run
Unit Tests: Documentation Validation / documentation (push) Waiting to run
Unit Tests: Proxy DB Operations / assert-shard-coverage (push) Waiting to run
Unit Tests: Proxy DB Operations / auth-checks (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / budgets (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / custom-logging (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / db-and-spend (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / endpoints-and-responses (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / guardrails-hooks (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / jwt-and-keys (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / key-generation (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / logging-misc (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-runtime (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-server-core (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-utils (push) Blocked by required conditions
Unit Tests / caching-local (push) Waiting to run
Unit Tests / core-utils (push) Waiting to run
Unit Tests / enterprise-package (push) Waiting to run
Unit Tests / enterprise-routing (push) Waiting to run
Unit Tests / integrations (push) Waiting to run
Unit Tests / All Other Providers (push) Waiting to run
Unit Tests / Vertex AI (push) Waiting to run
Unit Tests / misc (push) Waiting to run
Unit Tests / proxy-auth (push) Waiting to run
Unit Tests / proxy-endpoints (push) Waiting to run
Unit Tests / proxy-extras (push) Waiting to run
Unit Tests / proxy-infra (push) Waiting to run
Unit Tests / proxy-server (push) Waiting to run
Unit Tests / responses-caching-types (push) Waiting to run
GitHub Actions Security Analysis / zizmor (push) Waiting to run
feat(proxy): add TypeSafe AI Jev evaluate passthrough with registry-priced spend tracking
2026-09-17 16:37:33 -07:00
ryan
884a467a7f
fix(proxy): evict jwt_key_mapping cache when user, team, or org deletion removes mapped keys
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:33:59 +00:00
ryan-crabbe-berri
e5aa10a1ea
Merge pull request #41686 from BerriAI/litellm_member_budget_clone_reset_and_audit
...
fix(team): keep a forked member budget's reset window and audit bulk member budget writes
2026-09-17 16:32:31 -07:00
ryan-crabbe-berri
790c3ab71b
refactor(ui): move the model team selector into ModelTeamSelect to keep ModelInfoEditForm under the eslint line cap
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
LiteLLM Rust / rust-wheel (push) Has been cancelled
Terraform Provider / gofmt, vet, build, test (push) Has been cancelled
Terraform Provider / Provider endpoints vs proxy OpenAPI schema (push) Has been cancelled
2026-09-17 16:32:17 -07:00
Devin AI
44f90b5ba7
fix(proxy): seed member budget creates from the right source row
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:30:43 +00:00
ryan-crabbe-berri
89289d4f77
fix(proxy): surface a failed project spend enqueue at error level
...
LiteLLM Rust / rust-lint (push) Waiting to run
LiteLLM Rust / rust-test (push) Waiting to run
LiteLLM Rust / rust-wheel (push) Waiting to run
The call-site guard kept a project enqueue failure from skipping the sibling
spend writes, but logged it at debug only, so a dropped project charge was
invisible on a default log level. Log it through spend_log_error inside the
helper and re-raise, the way the org and agent helpers already do.
2026-09-17 16:26:26 -07:00
yassin
72ef7033c2
fix(mcp): freeze the session group counter behind MappingProxyType
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:26:06 +00:00
Devin AI
6db76b5f39
fix(ui): match the Team ID selector to the backend's proxy-admin-only bypass and show its placeholder
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 16:25:37 -07:00
Devin AI
500790a93a
fix(ui): keep every team selectable for org admins in the Team ID selector
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 16:25:37 -07:00
Devin AI
59693d5019
fix(ui): only offer team admins the teams they administer in the Team ID selector
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 16:25:37 -07:00
Devin AI
a7daa21df7
fix(ui): let admins change a model's team from the model edit page
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 16:25:17 -07:00
ryan-crabbe-berri
a282e3c78c
refactor(ui): build transformed model rows without in-place mutation
...
Greptile flagged the per-second fields for extending the transformer's
mutate-in-a-loop pattern. Map each raw model to a new object instead so no
field is assigned onto a shared reference, and drop the now unused
prefer-const suppression for the file
2026-09-17 16:24:55 -07:00
ryan-crabbe-berri
e4778cd2d1
test(proxy): drive the real spend queue in the project enqueue isolation test
...
Substitutes a queue that rejects project items instead of replacing writer
methods with mocks, so the test asserts the sibling key, team and tag spend
actually landed in the queue rather than that a mock was awaited.
2026-09-17 16:24:51 -07:00
ryan
de0047c802
fix(proxy): skip allowlist rewrite when the model name is unchanged
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:24:26 +00:00
yassin
33531649c3
perf(mcp): count gateway session groups with Counter and pin the oversized initialize peek invariant
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:20:47 +00:00
ryan
70164dabd2
fix(proxy): isolate project spend enqueue failures from sibling spend writes
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:20:10 +00:00
yassin
c230393731
fix(mcp): refuse sessionless and stale-session POSTs that skip initialize while mcp_allowed_clients is set
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:18:54 +00:00
ryan-crabbe-berri
10616d7407
Merge pull request #40875 from BerriAI/litellm_cache_leakage_all_models
...
fix(ui): list every provider in the cache leakage by-model table
2026-09-17 16:18:16 -07:00
Devin AI
7d65d9d774
fix(proxy): seed member budget forks from the row the membership points at
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:17:13 +00:00
ryan
d3f5cde530
fix(proxy): propagate db model renames to key, team, org, project and user model allowlists
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:11:52 +00:00
Mateo Wang
57d41bda29
Merge pull request #41684 from BerriAI/litellm_wildcard_license_auto_router
...
fix(license): let a wildcard allowed_features license grant the auto_router feature
2026-09-17 16:11:40 -07:00
Mateo Wang
07b5051c0d
Merge pull request #41689 from BerriAI/litellm_responses_bridge_strip_internal_kwargs
...
fix(responses): keep the addressed response id off bridged provider requests
2026-09-17 16:11:04 -07:00
yassin
aacbbe89d6
chore(proxy): regenerate OpenAPI snapshot and dashboard types for the Transcribe route docstring
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:10:23 +00:00
mateo-berri
1c40e6034d
fix(a2a): Entra credentials own the chat route bearer over a stored api_key or authorization header
2026-09-17 16:09:36 -07:00
mateo-berri
7f581f6bc7
fix(router): keep the TypeSafe key off caller-chosen Jev endpoints
2026-09-17 16:09:31 -07:00
yassin
912edaa8cc
Merge remote-tracking branch 'origin/main' into litellm_transcribe_passthrough
2026-09-17 23:07:57 +00:00
Mateo Wang
0da001901b
Merge pull request #41672 from BerriAI/litellm_autoroute_start_stop
...
feat(cli): rename lite autoroute up/down to start/stop, keeping the old names as deprecated aliases
2026-09-17 16:07:00 -07:00
yujonglee
ad5998072b
Merge pull request #41690 from BerriAI/litellm_extract_providers
...
refactor(rust): extract provider translations
2026-09-17 16:05:59 -07:00
Devin AI
9d5f65c26c
merge: resolve conflict with main, move temp budget patch fields to shared member_budget_patch
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 23:04:25 +00:00
ryan-crabbe-berri
f16c4e7a22
fix(team): drop a redundant None check on a non-nullable allowed_models column
2026-09-17 16:00:24 -07:00
ryan-crabbe-berri
29a959b3e8
Merge pull request #41632 from BerriAI/litellm_bulk_team_member_budget_update
...
feat(management_v1): bulk update team member budgets
2026-09-17 15:58:32 -07:00
yassin
ce735f586c
fix(proxy): scope Transcribe jobs to the key that started them and charge rewritten media the maximum
...
Standard jobs are tagged litellm-owner on StartTranscriptionJob so GetTranscriptionJob
and DeleteTranscriptionJob only work for the owner or a proxy admin, and account-wide
operations need a proxy admin. Media rewritten after job creation is charged the eight
hour maximum, and the success handler takes an injected log dispatch instead of tests
patching its private method
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:58:15 +00:00
mateo-berri
d3963e5d63
test(cli): pin the up alias port forwarding and the removed-settings stop message
2026-09-17 15:55:50 -07:00
Yujong Lee
6ce78b85a5
refactor(rust): remove core provider reexports
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:55:15 +00:00
mateo-berri
79029d89f9
test(responses): drop the history docstrings from the bridge regression tests
2026-09-17 15:51:35 -07:00
kerry
91619376d2
test: restore azure ai cached-token billing coverage with derived rates
...
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
LiteLLM Rust / rust-wheel (push) Has been cancelled
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:49:02 +00:00
Mateo Wang
289c52bcd6
Merge pull request #39512 from BerriAI/litellm_fix_image_edits_bracketed_alias
...
fix(images): stop forwarding the raw image[] and mask[] form keys
2026-09-17 15:48:32 -07:00
Yujong Lee
558022c3dd
refactor(rust): extract provider translations
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:46:02 +00:00
Mateo Wang
fec8231b83
Merge pull request #41419 from BerriAI/litellm_bedrock_openai_no_cachepoint
...
fix(bedrock): never emit Converse cachePoint for OpenAI-family models
2026-09-17 15:43:04 -07:00
ryan-crabbe-berri
f04f0258f7
refactor(team): model the bulk budget audit payload as frozen types
2026-09-17 15:41:06 -07:00
ryan
1c0342332b
refactor(proxy): keep project spend enqueue within lint ceilings
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:40:07 +00:00
yucheng
e9825f1d26
test(proxy): drive the heuristics responsiveness check without mutable state
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:39:15 +00:00
mateo-berri
1feaa48705
fix(proxy): log TypeSafe calls that name no model as unknown
2026-09-17 15:37:00 -07:00
yassin
313093a8a0
fix(ui): gate MCP live connections tab to proxy admin tier roles
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:36:00 +00:00