yassin
ce735f586c
fix(proxy): scope Transcribe jobs to the key that started them and charge rewritten media the maximum
...
Standard jobs are tagged litellm-owner on StartTranscriptionJob so GetTranscriptionJob
and DeleteTranscriptionJob only work for the owner or a proxy admin, and account-wide
operations need a proxy admin. Media rewritten after job creation is charged the eight
hour maximum, and the success handler takes an injected log dispatch instead of tests
patching its private method
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:58:15 +00:00
mateo-berri
d3963e5d63
test(cli): pin the up alias port forwarding and the removed-settings stop message
2026-09-17 15:55:50 -07:00
Yujong Lee
6ce78b85a5
refactor(rust): remove core provider reexports
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:55:15 +00:00
mateo-berri
79029d89f9
test(responses): drop the history docstrings from the bridge regression tests
2026-09-17 15:51:35 -07:00
kerry
91619376d2
test: restore azure ai cached-token billing coverage with derived rates
...
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
LiteLLM Rust / rust-wheel (push) Has been cancelled
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:49:02 +00:00
Mateo Wang
289c52bcd6
Merge pull request #39512 from BerriAI/litellm_fix_image_edits_bracketed_alias
...
fix(images): stop forwarding the raw image[] and mask[] form keys
2026-09-17 15:48:32 -07:00
Yujong Lee
558022c3dd
refactor(rust): extract provider translations
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:46:02 +00:00
Mateo Wang
fec8231b83
Merge pull request #41419 from BerriAI/litellm_bedrock_openai_no_cachepoint
...
fix(bedrock): never emit Converse cachePoint for OpenAI-family models
2026-09-17 15:43:04 -07:00
ryan-crabbe-berri
f04f0258f7
refactor(team): model the bulk budget audit payload as frozen types
2026-09-17 15:41:06 -07:00
ryan
1c0342332b
refactor(proxy): keep project spend enqueue within lint ceilings
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:40:07 +00:00
yucheng
e9825f1d26
test(proxy): drive the heuristics responsiveness check without mutable state
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:39:15 +00:00
mateo-berri
1feaa48705
fix(proxy): log TypeSafe calls that name no model as unknown
2026-09-17 15:37:00 -07:00
yassin
313093a8a0
fix(ui): gate MCP live connections tab to proxy admin tier roles
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:36:00 +00:00
mateo-berri
ca91751d5b
fix(responses): keep the addressed response id off bridged provider requests
...
The Responses id security hook keeps the id a client addressed under
`_litellm_addressed_response_id` in the request body so internal retries can
re-authorize it. On a model without a native Responses config that body is
bridged into `completion()` kwargs, the key was treated as a provider param,
and providers rejected it, so every follow-up turn carrying
`previous_response_id` returned 400.
Register the key in `all_litellm_params` so it is dropped before any provider
request, and share one constant between the hook and the param list.
2026-09-17 15:35:11 -07:00
jesus
1b69a5b0a4
test(proxy): model missing organizations in MCP auth fixtures
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:34:02 +00:00
ryan
7e5b3b49d4
fix(proxy): treat non-positive project max_budget as unbudgeted
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:33:54 +00:00
kerry
0b58281038
Merge remote-tracking branch 'origin/litellm_remove_brittle_price_pinning_tests' into litellm_remove_brittle_price_pinning_tests
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
# Conflicts:
# tests/test_litellm/proxy/common_utils/test_prompt_cache_pricing.py
2026-09-17 22:33:53 +00:00
kerry
b054d54bee
Merge remote-tracking branch 'origin/litellm_remove_brittle_price_pinning_tests' into litellm_remove_brittle_price_pinning_tests
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
# Conflicts:
# tests/test_litellm/llms/parallel_ai/test_parallel_ai_search.py
# tests/test_litellm/proxy/common_utils/test_prompt_cache_pricing.py
# tests/test_litellm/proxy/test_proxy_utils.py
2026-09-17 22:33:26 +00:00
kerry
4be0cf96b2
test: treat null long-context rates as absent when deriving cache cost expectations
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:33:09 +00:00
kerry
9eb6fbc572
test: read cost-map keys the implementation resolves and isolate the tariff test's model_cost copy
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:32:39 +00:00
ryan
bde5593523
Merge remote-tracking branch 'origin/main' into litellm_lit_3269_project_spend_tracking
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
# Conflicts:
# litellm/proxy/common_utils/reset_budget_job.py
2026-09-17 22:29:16 +00:00
jesus
c4ad6194a0
fix(auth): only fail closed on DB outages during org lookup
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:28:11 +00:00
yucheng
36844ef301
fix(proxy): clamp prompt injection heuristics worker count to at least one
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:26:00 +00:00
mateo-berri
4371ddb620
feat(cli): keep lite autoroute up and down as hidden deprecated aliases
2026-09-17 15:25:12 -07:00
yassin
52914a06d2
Merge remote-tracking branch 'origin/main' into litellm_mcp_client_allowlist
2026-09-17 22:22:28 +00:00
kerry
eb2be3758a
test: read cost expectations from the catalog row the code bills against
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:22:24 +00:00
yassin
5f6702ee47
fix(mcp): admit an allowlisted initialize that fills the peek cap exactly and type the allowlist test helpers
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:22:19 +00:00
ryan-crabbe-berri
775b83bcf4
refactor(team): drop null limits and ISO-format timestamps in the bulk budget audit payload
2026-09-17 15:19:35 -07:00
kerry
e8f098f38e
test: hoist the json import to module scope
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:18:18 +00:00
kerry
26addc5b39
test: fix remaining cost-map pin and leaked logging event races
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:17:27 +00:00
ryan-crabbe-berri
909a30d6a1
fix(team): keep a forked member budget's reset window and audit bulk member budget writes
...
Forking a shared budget row rebuilt budget_reset_at from the duration, so editing
an unrelated limit restarted the member's window while their spend carried over:
a tpm bump quietly handed them a fresh period. The fork now inherits the source
row's deadline, and only recomputes when the patch actually sets budget_duration.
The bulk member budget route now writes one audit entry per call, a team-scoped
'updated' row carrying every written member's limits before and after, matching
what /team/member_add already records for membership changes. It honors the
litellm-changed-by header like the other audited team routes.
2026-09-17 15:17:00 -07:00
yassin
a9ab7392ae
feat(mcp): show live gateway sessions by AI client and user
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:15:55 +00:00
jesus
ee9294af53
test(auth): annotate centralized auth mocks
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:08:45 +00:00
mateo-berri
c2fbb11dca
fix(license): let a wildcard allowed_features license grant the auto_router feature
2026-09-17 15:08:09 -07:00
kerry
bbde2f8a3a
docs(e2e): name the govcloud env vars in the coverage matrix row
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:07:50 +00:00
jesus
79b6cd2917
fix(auth): treat a missing org row as no org limits
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:03:16 +00:00
jesus
4a13ebbc5b
fix(auth): fail closed on org lookup errors when DB is required
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 22:01:50 +00:00
Yassin Kortam
356b8d4074
Merge pull request #41444 from zachbernstein-sdx/fix/scim-pagination-count-clamp
...
fix(scim): align pagination `count` validation with RFC 7644
2026-09-17 14:59:22 -07:00
mateo-berri
4669041ae8
fix(a2a): copy registered agent headers so one caller's bearer never reaches the next
...
The chat route handed the registry's stored headers dict straight to validate_environment, which wrote the caller's bearer into it, so the next caller of the same agent with no key of their own sent the previous caller's token. The registry lookup now copies the stored headers and validate_environment returns a new dict instead of mutating its input. A regression test drives two completions through one registered agent and asserts the second carries no Authorization and the stored agent is unchanged.
2026-09-17 14:58:50 -07:00
yassin
4885594a1e
fix(proxy): use path-style S3 URLs for dotted Transcribe media buckets
...
Virtual-hosted URLs for bucket names containing dots fail TLS verification, so the
media duration fetch failed and completed jobs were charged the eight hour maximum
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:55:32 +00:00
Mateo Wang
80b0a875dc
Merge pull request #41673 from BerriAI/litellm_deprecate_litellm_proxy_entrypoint
...
feat(cli): deprecate the litellm-proxy entrypoint in favour of lite
2026-09-17 14:54:47 -07:00
jesus
87c00bf47b
fix(auth): place strict lint exemption on org lookup
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:51:18 +00:00
kerry
6858663fd2
test: share the video cost expectation helper and trim the gate workflow triggers
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:51:06 +00:00
jesus
cc875a6eb3
fix(auth): exempt org lookup fallback from strict lint
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:51:06 +00:00
kerry
bdd9335116
docs(e2e): list the govcloud bedrock test as a coverage matrix row
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:51:02 +00:00
mateo-berri
255190ca35
Merge remote-tracking branch 'origin/main' into litellm_fix_image_edits_bracketed_alias
2026-09-17 14:49:54 -07:00
kerry
c988a5002b
ci: gate changed tests against a mutated cost map
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:49:16 +00:00
kerry
ccff1fa95f
test: derive the remaining cost-map pins from the catalog entry
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:49:16 +00:00
kerry
4b45fd5f44
docs(e2e): drop govcloud keys from the contributing starter env
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-17 21:47:21 +00:00
yassin
fb99e3dde3
Merge remote-tracking branch 'origin/main' into litellm_mcp_client_allowlist
2026-09-17 21:46:21 +00:00