- Reject group operations when users don't exist (security fix)
- Prevents unauthorized user provisioning via group membership
- Aligns with SCIM 2.0 protocol: users must exist before group membership
- Add validation for empty user IDs
- Update tests to verify rejection behavior
This is a breaking change but necessary for security and SCIM compliance.
Users must be created via POST /Users before being added to groups.
* fix: lazy load utils.py imports
Lazy-load most functions and response types from utils.py to avoid loading
tiktoken and other heavy dependencies at import time. This significantly
reduces memory usage when importing completion from litellm.
* fix: prevent memory leak in aiohttp connection pooling
Add connection limits to aiohttp TCPConnector to prevent unbounded
connection growth that causes memory leaks. Without these limits,
aiohttp's _wrap_create_connection can accumulate connections
indefinitely in long-running processes.
Changes:
- Set default limit of 300 total connections and 50 per host
- Apply limits to shared proxy session initialization
- Apply limits to HTTP handler transport creation
- Configurable via AIOHTTP_CONNECTOR_LIMIT and
AIOHTTP_CONNECTOR_LIMIT_PER_HOST environment variables
- Set to 0 for unlimited (not recommended for production)
This fix covers:
- All standard LLM provider API calls (OpenAI, Anthropic, etc.)
- Proxy server shared session
- Most guardrail HTTP calls
Impact: Prevents memory exhaustion in high-traffic deployments and
long-running proxy servers that make thousands of API calls.
Testing: Verified connection limits are applied correctly and
existing functionality remains unchanged.
Add Agent Lightning, Microsoft's open-source framework for training
AI agents with RL, APO, and SFT. Uses LiteLLM Proxy for LLM routing
and trace collection.
- Test user with UUID in user_email (defensive fix scenario)
- Test user with None email (root cause fix scenario)
- Verifies transformation doesn't fail and emails array is empty for invalid emails
Root cause fix:
- Set user_email=None instead of user_id when creating users without email (scim_v2.py line 313)
- Prevents UUIDs from being stored in user_email field in the first place
Defensive fix:
- Add validation in scim_transformations.py to check if user_email contains '@' before creating SCIMUserEmail
- Handles existing users in database that may have UUIDs in user_email field
- Prevents validation error when transforming users to SCIM format
Fixes issue where GET /Users returns 500 error with message:
'value is not a valid email address: An email address must have an @-sign'
* fix(initial-commit): adding a way to get the right response type based on the api route
* feat(unified_guardrail.py): support streaming guardrails
* test: update tests
* fix: fix linting errors
* test: update tests