Commit graph

46528 commits

Author SHA1 Message Date
mateo-berri
6bf535bb8f feat(e2e): fail passed replays that leave recorded interactions unconsumed 2026-08-18 14:34:23 -07:00
yuneng-jiang
2e44689ea0
refactor(ui): migrate SSO, SCIM and vault forms to react-hook-form and shadcn (#37347)
* refactor(ui): migrate the SCIM and Hashicorp Vault forms to react-hook-form and shadcn

Both forms move off antd Form onto react-hook-form plus the shadcn kit, with
neutral greys on semantic tokens and coloured callouts keeping their hue behind
a dark variant, so both are dark-mode ready.

Neither file had a test, so each one gained a characterization test written
against the antd original and proven green there before any source changed. The
same files pass unedited after the migration.

Two payload details the migration has to reproduce rather than tidy up. antd
onFinish emits a mounted but never-set field as a key holding undefined, and the
vault handler turns each of those into an empty string to clear it server-side,
so every rendered vault field is seeded to an empty string rather than left
absent. And the vault form still refuses to seed or send a blank sensitive
field, so a stored secret stays write-once.

SCIM keeps its Enter-to-submit path: its footer button was a Tremor Button
carrying an explicit type=submit, which Tremor forwards, so the form could
already be submitted from the keyboard.

* refactor(ui): migrate SSO, SCIM and vault forms to react-hook-form and shadcn

Moves the SSO settings form graph, the SCIM token form and the Hashicorp
Vault config form off antd Form onto react-hook-form plus the shadcn
FormField primitives, keeping today's submit payloads byte for byte.

The SSO graph migrates atomically because an antd Form.Item parent cannot
host a react-hook-form child. BaseSSOSettingsForm now owns the shared
schema, the field components and a mounted-field picker that reproduces
what antd's onFinish actually sent: rc-field-form validates only mounted
entities, so hidden provider and mapping fields never reached the wire.
submitMountedSSOValues keeps that behaviour explicit instead of leaving it
to which fields happen to be rendered.

EditSSOSettingsModal seeds through an explicit mapper rather than
spreading the server record, so a field the form does not declare cannot
leak into an update. The vault modal keeps its two distinct behaviours for
blank inputs, clearing non-sensitive fields with an empty string and
omitting blank secrets so a stored credential survives a save.

* fix(ui): render SSO select labels and guard seeding completeness

The migrated Select triggers rendered the raw stored value rather than the
option label, so an untouched Default Role showed "internal_user" and a
chosen provider showed "okta". Base UI resolves a label only through a
Value function child, so both selects now format through the same option
list that builds their items.

Adds three characterization cases the earlier suite did not reach: an
empty required provider credential blocks the submit and names the field,
reopening the modal against a different stored config replaces every
seeded value rather than merging, and every field the provider forms can
mount survives the seeding mapper. The last one fails by name when a key
is dropped from that mapper, which is the class of defect an explicit
allowlist invites.

* test(ui): cover the edit SSO modal against its real form tree

The existing modal test stubs BaseSSOSettingsForm out, so no field ever
registers and validation passes trivially. Rewiring the Save button to
call the submit handler with raw form values, skipping both validation and
the mounted-field filter, left all 112 tests green.

Adds an integration test that renders the real modal, the real form body
and the real antd shell, stubbing only the two data hooks. Clearing a
required credential now blocks the save and names the field, and a valid
save asserts the exact payload. The bypass mutation fails both cases, and
dropping only the mounted-field filter fails the payload one.
2026-08-18 14:30:17 -07:00
ryan-crabbe-berri
ef72e1afd6
refactor(ui): move the tag and vector store views off tremor (#37311)
* refactor(ui): move the search tool, tag and vector store views off tremor

Swaps the tremor Button, TextInput, Text, Title, Card, Badge, Accordion and
TabGroup usages in the search tools, tag management and vector store views for
the shadcn primitives, following the tremor conversion cookbook. Both tab panels
in the vector store info view carry keepMounted so the tester's state survives
switching to Details and back, and a test pins that contract.

tremor's Button renders a bare button element with no type, so inside the antd
Forms here the Test Connection button in the create search tool modal and the
Cancel buttons in the tag editor and the vector store form were implicit submit
buttons. The shadcn Button defaults to type="button", so they can no longer
submit, and every button that is meant to submit now carries an explicit
type="submit". Clicking Test Connection and Cancel against a live proxy on the
merge base already only ran the connection test and only cancelled, so this
closes a latent trap rather than changing what the pages do.

Decrements the seven no-restricted-imports suppression counts these files no
longer need, leaving the antd half of each entry in place for the antd pass.

* refactor(ui): use the line tab strip in the vector store detail view

The detail view's tabs kept the default pill TabsList, so it no longer matched
the underline strip tremor rendered before the swap or the one the vector store
list view already uses.

* test(ui): pin the tag and vector store form save and cancel buttons

Cancel in the tag editor used to submit the form and save the tag because the
tremor button carried no type; nothing in the suite failed if it started doing
that again. Each form now has a pair of cases: Save Changes and Create still
submit, and Cancel leaves the record alone.

* fix(ui): keep the reveal toggle on the search tool API key

tremor's TextInput drew its own show/hide button whenever the type was
password, and the shadcn Input is a plain native input, so the straight
prop pass-through silently deleted that affordance from the create search
tool form's API key field.

Puts it on antd's Input.Password instead, which is what the sibling edit
form in the same directory (SearchTools.tsx) already uses for the very
same field, so the reveal survives and the two forms behave the same.
The file already imports antd, so this adds no import and no suppression.
2026-08-18 14:29:06 -07:00
Tianhe Zhang
4f4892efcb fix(spend-logs): sync root prisma schema 2026-08-18 14:29:02 -07:00
yuneng-jiang
573aa61084
refactor(ui): move the shared key form controls off antd onto shadcn (#37348)
* test(ui): pin the antd submit payloads for the key create and edit forms

Characterization only, no source change. Both suites are green against the
current antd components, so they can gate the react-hook-form migration that
follows without being edited.

key_edit_view had no exact-payload assertion, only objectContaining, so nothing
caught a form that started sending server-only key fields. The new case asserts
the whole object.

create_key_button's existing suite runs against a hand-rolled antd fake and
stubs out KeyLifecycleSettings and RateLimitTypeFormItem, so neither the real
store nor those two controls were covered. The new file drives the real antd
form and pins the network payload instead.

* refactor(ui): move the shared key form controls off antd onto shadcn

KeyLifecycleSettings and RateLimitTypeFormItem each owned an antd Form.Item and
took the parent's FormInstance as a prop, so neither could be hosted by anything
but an antd form. That is what made the key create and edit forms one
inseparable migration unit.

Both are now presentational: they take value and onChange and let the parent own
the binding, so an antd Form.Item and a react-hook-form FormField can host them
equally. The two parents keep their antd forms for now and pass the binding down
unchanged, which is why every existing payload assertion still holds.

Controls are shadcn Select, Input, Switch and Checkbox on semantic colour
tokens, so both are dark-mode ready. The rotation notice keeps its blue hue and
gains a dark variant rather than flattening to a neutral.

The form prop the two components took was already inert: antd dispatches its own
store update before calling the child's onChange, so setFieldValue was writing a
value the store had just been given.

KeyLifecycleSettings.test.tsx keeps every assertion; only the harness moves the
duration binding up into a Form.Item, and one case disables user-event's
pointer-events check because Base UI leaves a reopened select popup inert under
jsdom, reproduced on a bare shadcn Select with none of this code involved.

* test(ui): pin the role-gated key fields and tidy the new assertions

Adds the case that proves policies and prompts leave the payload entirely for a
role that cannot see them, which a react-hook-form port would otherwise start
sending from defaultValues. Green against antd like the rest.

Also hoists the two large expected payloads into named constants and drops two
unused exports, so the lane adds no new lint-budget pressure.

* fix(ui): give the key expiry input and Never Expire checkbox separate labels

The expiry label carried htmlFor for the duration input while also wrapping
the Never Expire checkbox and its own label, so the two controls shared one
ambiguous association. Splitting the row into a plain container with a label
per control makes each name resolve to the control it describes.

Also drops the prop and test comments added in this branch, which the
repository comment policy does not allow.

* test(ui): pin the create-form expiry binding to the generate payload

create_key_button coalesces a missing or blank duration to null before it
calls keyCreateCall, so the key is present in the payload whether or not the
control is bound to the form. Every existing case stayed green with the
Form.Item removed, which left the binding uncovered.

The new case opens Key Lifecycle, types an expiry, and asserts it arrives as
that value. Proven red with the Form.Item removed and green with it restored.
2026-08-18 14:28:03 -07:00
yuneng-jiang
76ff0d5351
refactor(ui): migrate the model settings and credential rotation modals to react-hook-form and shadcn (#37342)
* refactor(ui): migrate the model settings and credential rotation modals to react-hook-form

Both modals owned a self-contained antd FormInstance with no shared form
children, so each migrates on its own without touching the add_model graph.

ModelSettingsModal keeps its antd Modal shell, footer buttons and Skeleton
placeholder. The single store_model_in_db field becomes a shadcn Switch inside
a FormField, the antd Form.Item tooltip stays a hover tooltip rather than
becoming always-visible description text, and the remount-on-new-config
behaviour that the antd `key` provided is now RHF's `values` option.

UpdateModelCredentialsModal keeps the antd Modal and warning Alert. The
Input.Password becomes an InputGroup with an Eye/EyeOff reveal toggle so the
reveal affordance survives, and the required rule ports to the same message.
Both submit paths stay exactly as they were: Enter still submits here because
the antd Form had onFinish and a real submit button, while the settings modal
keeps submitting only from its footer button.

* refactor(ui): reuse the shared PasswordInput in the credential rotation modal
2026-08-18 14:28:00 -07:00
Mateo Wang
5d1401342a
Merge pull request #33195 from Sujithr07/fix/33184-store-prompt-cache-key
fix(main): forward store and prompt_cache_key params on chat completions
2026-08-18 14:22:00 -07:00
mateo-berri
803113c63a fix(proxy): estimate failed-request input tokens on /v1/messages and count system prompts
The Anthropic messages endpoint's exception handler passed the raw
request body dict to the failure hook, but request setup had already
replaced the processor's dict with one carrying the logging object, so
failure rows for /v1/messages never lifted recovered or estimated usage.
Pass the processor's dict instead.

The input-side estimate only counted the messages list, missing the
Anthropic top-level system prompt (string or text-block list) and the
Responses API instructions field, which live in optional_params. Count
them too.
2026-08-18 14:21:47 -07:00
Mateo Wang
1b77dbc71e
Merge pull request #37345 from BerriAI/litellm_lit_5720_openai_responses_prefix
fix(responses): strip the responses/ routing prefix on the Responses API path
2026-08-18 14:21:27 -07:00
ryan-crabbe-berri
d9e9270574
refactor(ui): move the internal user create, edit and detail views off tremor (#37309)
* refactor(ui): move the internal user create, edit and detail views off tremor

The tremor SelectItem rows nested inside the antd role Select become
antd Select.Option so the antd control keeps driving the form; the antd
removal is left to the antd pass. The user detail tabs move from a
numeric index to overview/details slugs (the public initialTab number
prop is unchanged and mapped at the boundary), every panel is
keepMounted, and a test pins that contract. The per-team remove button
keeps tremor's light red look as a ghost icon button rather than a
solid destructive one. Prunes the tremor no-restricted-imports
suppressions these files no longer need.

* refactor(ui): keep the user detail tab strip on the line variant

The tremor TabList defaulted to the underline strip, so the shadcn
TabsList needs variant="line" to keep that look instead of the filled
segmented pill; the triggers pick up the same active classes the users
page strip right above already uses. Also drops the vestigial empty
placeholder on the embedded create user email field, which only existed
to suppress tremor's built-in "Type..." hint.
2026-08-18 21:17:36 +00:00
Tianhe Zhang
607e4a4e30 feat(spend-logs): add lifecycle timestamps 2026-08-18 14:16:08 -07:00
mateo-berri
be594f5984 feat(guardrails): count bedrock guardrail cost against spend and budgets
Price ApplyGuardrail usage units recorded by PR #37225 with a new
bedrock/guardrails entry in the model cost map (regional override via
bedrock/{region}/guardrails), add the per-request guardrail_cost to the
standard logging payload's response_cost and CostBreakdown, surface it in
the x-litellm-response-cost header, and bill blocked requests through the
failure hook so key and team budgets see what AWS bills
2026-08-18 14:16:07 -07:00
Mateo Wang
f119a83adc
Merge pull request #36240 from BerriAI/litellm_fix_chained_proxy_file_upload
fix(router): forward target_model_names on file uploads to litellm_proxy deployments
2026-08-18 14:15:44 -07:00
Mateo Wang
d03ef8be03
Merge pull request #36246 from BerriAI/litellm_lit_5307_advisor_router
fix(advisor): resolve the advisor sub-call through the proxy router
2026-08-18 14:09:54 -07:00
Mateo Wang
840c5f680d
Merge pull request #37242 from bruno-olivia/litellm_fw_skip_prefix_rewrite
fix(fireworks): skip accounts/ rewrite for FW-* Foundry deployment ids
2026-08-18 14:09:49 -07:00
tin-berri
1f4acbb924
feat(complexity_router): custom classifier plugins via classifier_type 'custom' (#37249)
* feat(complexity_router): custom classifier plugins via classifier_type 'plugin'

Adds a third classification mode where an operator-supplied hook decides the
tier instead of the heuristic scorer or the LLM classifier. The hook implements
an async classify(context) returning a tier name (built-in value, tier_labels
label, or tier_definitions name) or None to decline; failures, timeouts, and
unknown tiers fall back exactly like a failed LLM classifier. The context
carries the request messages and metadata, including caller identity, so a
plugin can route by team, spend, or any business rule.

The plugin resolves from a dotted path at proxy startup with a load-time check
that classify is a coroutine function, and is closed off over HTTP like the
routing plugins list. Routing decisions record the new classifier_plugin cause.
tier_definitions now accepts classifier_type 'plugin' alongside 'llm'.

* fix(proxy): resolve plugin dotted paths in _delete_deployment before hashing ids

The db-sync reconcile re-reads the raw config and hashes litellm_params to
compute which ids the config wants served, but the router's ids were hashed
from the resolved params where plugin dotted paths are live instances. The
mismatched ids made the reconcile evict every plugin-bearing auto-router one
sync after startup, on any proxy with a database connected. This also affected
the existing routing plugins list, not just the new classifier plugin.

Resolving the plugins in _delete_deployment the same way load_config does makes
both sides hash the same canonical form. A plugin module broken on disk at
reconcile time skips cleanup instead of evicting valid deployments, matching
how a get_config failure is handled

* fix(complexity_router): treat non-string plugin verdicts as declines, centralize the empty-mapping sentinel

A hook returning a non-string raised inside resolve_classified_tier outside the
plugin exception boundary, failing the request instead of falling back. Also
moves the read-only empty mapping to constants.py per repo convention and moves
the classifier plugin product docs out of the package README for the docs repo

* refactor(complexity_router): rename the plugin classifier mode to classifier_type 'custom'

The mode value now names the operator's intent while classifier_plugin keeps
naming the mechanism; routing decisions keep the classifier_plugin cause

* refactor(proxy): pin plugin-bearing deployment ids from the raw params instead of resolving in the reconcile

Replaces the previous approach of re-running plugin resolution inside
_delete_deployment, which imported operator modules on every reconcile cycle
and skipped the whole cleanup pass when any one module was broken on disk.
load_config now stamps model_info.id from the raw litellm_params before
resolution swaps dotted paths for live instances, so the reconcile's raw-config
hash matches by construction and needs no resolution at all: a broken module
cannot stall cleanup for unrelated models, and any future param-transforming
resolution is covered by the same pin. _generate_model_id becomes a staticmethod
so the pin can run before the Router exists; its statically dead non-string key
branches are removed. Also documents candidate_models as an informational
snapshot for classifier plugins, unlike the narrowing surface RoutingPlugin
filters

* fix(router): restore _generate_model_id key handling, align classifier context with the routing-plugin pattern

The staticmethod conversion accidentally dropped the non-string-key branches
from _generate_model_id, a silent hash change for any params with non-string
keys; they are restored verbatim. The classifier plugin context now follows
the Router-level routing-plugin recipe exactly: structured messages come from
resolve_structured_messages over the raw messages, and the metadata key comes
from the shared get_metadata_variable_name_from_kwargs helper, which also
replaces the duplicated inline sniff in _pick_model_for_tier. This removes the
raw-or-resolved fallback where a plugin could silently receive resolved
messages when a call site forgot to pass the raw ones

* refactor(router): make generate_model_id public, guard classifier context construction

Two modules legitimately hash deployment ids with the same helper now (Router
and the proxy's config-load pin), so the private name was lying about its
audience and the cross-module call needed a pyright suppression; renaming it
public restores the static safety net. The classifier plugin's RoutingContext
construction moves inside the failure boundary, matching the LLM path where
litellm-side prompt building also falls back rather than failing the request,
and a prompt-only call with no message list is now covered by a test
2026-08-18 14:09:19 -07:00
mateo-berri
2adf8aa581 feat(e2e): add record/replay transport seam and fixture bundle format
E2E_FIXTURE_MODE selects the transport every e2e client is built on: live
(default, unchanged behavior), record (pass through to the live proxy while
writing every interaction to a fixture bundle), or replay (serve every
interaction from the bundle with no proxy and no provider spend). Both new
transports fulfil the existing Transport protocol, so no test changes shape.

A bundle is a directory with a manifest (record timestamp, harness version,
format version) and one JSON file per interaction, grouped per test in call
order. Replay against a manifest older than seven days hard-fails at
collection time naming the bundle age. Record always wipes and never reads
the previous bundle, refusing to wipe a directory that is not a bundle.
Auth header values are redacted on write; uploads store a sha256 digest.
unique_marker() becomes deterministic per test in record/replay modes so a
replay run regenerates exactly the requests the record run sent.

Content-based match keys, streaming chunk fidelity, and provider-scoping are
follow-ups (LIT-5741, LIT-5742, LIT-5745).
2026-08-18 14:08:00 -07:00
ryan-crabbe-berri
fca470a64b
refactor(ui): move the MCP server forms and detail tabs off tremor (#37329)
* refactor(ui): move the MCP server forms and detail tabs off tremor

Swaps the tremor Button, TextInput, Title, Text and Tab primitives in the six
MCP server components for the shadcn layer, and leaves the antd Modals, Forms
and Selects alone for the antd pass. In the two files that mix both input
libraries, antd's Input is imported as AntdInput so the shadcn Input keeps its
canonical name.

Two behaviours needed care. Base UI's Button forces type="button", so the
create button in CreateMCPServer now carries an explicit type="submit"; Cancel
and the OAuth authorize button stay non submitting, which also drops the
accidental implicit submit they inherited from tremor. Every TabsContent gets
keepMounted, because Base UI unmounts inactive panels while tremor only hid
them, and a save started from the Cost Configuration tab reads fields that live
in the Server Configuration panel. mcp_server_edit.test.tsx gains a regression
test for that: drop keepMounted and the pending edit never reaches the update
payload.

One affordance is gone: password fields no longer draw tremor's built in reveal
toggle, since the shadcn Input is a plain native input.

Prunes the six no-restricted-imports suppressions these files no longer need.

* fix(ui): keep the reveal toggle on the MCP secret fields

tremor's TextInput drew its own show/hide button whenever the type was
password, and the shadcn Input is a plain native input, so the straight
prop pass-through silently deleted that affordance from five fields: the
create modal's authentication value and the OAuth client id and secret in
both the M2M and the interactive flow.

Puts them on antd's Input.Password instead, which is what every sibling
secret field in this directory already uses (TokenExchangeFormFields,
IdJagFormFields, AwsSigV4Fields and the edit form), so the reveal survives
and the five fields now match their neighbours instead of behaving
differently inside the same form. Both files already import antd, so this
adds no import and no suppression.

* test(ui): pin the connect tab mount contract

mcp_connect's per-card "limit tools to specific MCP servers" toggle lives
in panel local state that feeds the rendered header block, so the panels
have to stay mounted across a tab switch. Base UI unmounts an inactive
panel unless keepMounted is set, and unlike the edit form there was no
test holding that down.

Toggles the header on from the LiteLLM Proxy panel, switches to Cursor and
back, and asserts both the switch and the x-mcp-servers line in the curl
example survived. Dropping keepMounted from that panel fails it.

* fix(ui): keep the MCP tab strips underlined instead of segmented

A bare tremor TabList is variant="line", so the connect strip and the
server settings strip both drew an underlined tab on a full width
divider. Converting them bare turned each into a filled segmented
control, because the shadcn TabsList defaults to the pill.

Both strips now use variant="line" with the divider recipe, and the
connect strip gets back the grey rounded box tremor drew around its four
tabs.
2026-08-18 21:07:36 +00:00
yuneng-jiang
5997ef0423
refactor(ui): migrate the vector store creation form to shadcn (#37353)
* refactor(ui): migrate the vector store creation form to shadcn

CreateVectorStore and S3VectorsConfig were the last antd Form.Item users on
the vector stores page. Both are now built from the shared Field primitives
and shadcn controls, so the page picks up the design tokens and dark mode.

CreateVectorStore's antd Form was inert: no Form.Item carried a name, there
was no onFinish, and the submit button sat outside the form element, so the
form store never held anything. Form.useForm is dropped rather than replaced
with react-hook-form, and the existing imperative validation is unchanged.

S3VectorsConfig's four Form.Item wrappers had no name either, so its inputs
were already prop-controlled and decoupled from the parent store. The
embedding model picker keeps its typeahead by moving to Combobox.

The submit payload is unchanged. A new characterization suite pins it: it was
written against the antd originals, proved green there first, and passes
unedited against the migration.

* test(ui): cover the S3 embedding model combobox end to end

The migration moved this control from an antd Select with showSearch to a
Combobox, and nothing exercised it: the suite pinned the payload but never
loaded the option list, filtered it, or selected from it.

The case drives the whole interaction. It stubs three models, one of which is
a chat model, opens the list and asserts the chat model is absent, types to
filter, selects the remaining embedding model and asserts it arrives in the
providerParams argument.

Proved green against the antd originals of both files first, then unedited
against the migration. It queries the control by role rather than by label,
because the antd original rendered a label with no control associated to it,
which the migration fixes.
2026-08-18 21:07:19 +00:00
mateo-berri
d2fbaff2c9 fix(proxy): record estimated input tokens in spend logs for dispatched failed requests
Failure rows in the spend log only carried token counts when a broken
stream stashed recovered partial usage; non-stream requests that reached
the provider and then failed (timeouts, provider 4xx/5xx) logged
0/0/0 even though the provider billed the input tokens. Estimate the
input side in post_call_failure_hook with the same tokenizer fallback
interrupted streams use, gated to requests that were actually dispatched
(first_api_call_start_time set and no litellm_no_upstream_llm_call
marker), and pin response_cost to 0.0 so failed requests never bill
spend. Recovered partial-stream usage still wins over the estimate.
2026-08-18 14:05:28 -07:00
yuneng-jiang
0cc2f29c78
refactor(ui): migrate pass-through, project and access group forms to react-hook-form and shadcn (#37354)
Moves six antd Form graphs onto react-hook-form + shadcn: the pass-through
create and edit forms with their two shared sections, the project create and
edit modals, and the access group edit modal.

Each form graph moved atomically. An antd Form.Item parent cannot host a
react-hook-form child, so a shared section that renders a Form.Item has to move
with every parent that mounts it or the field silently stops reaching the
payload. PassThroughSecuritySection holds Form.Item name="auth" and is imported
by both pass-through parents, so all four files move together.

Submit payloads are unchanged and pinned by characterization tests written
against the antd originals first. That includes the parts that look like bugs:
add_pass_through still sends timeout and cost_per_request as strings while
pass_through_info sends them as numbers, and both edit modals still omit fields
whose antd Form.Item never mounted.

One behaviour does change. Enter in the add pass-through form ran Cancel and
discarded the filled form, because HTML implicit submission activates the first
submit button in tree order and Tremor renders buttons with no type attribute,
making the footer Cancel that button. Cancel is now type="button" and Enter
submits.
2026-08-18 14:05:23 -07:00
mateo-berri
9b837fccde test: parameterize the bridge tool turn fixture return type 2026-08-18 14:05:21 -07:00
yuneng-jiang
85333b286d
refactor(ui): migrate the caching, cost tracking, alerting and user detail forms to react-hook-form and shadcn (#37350)
* refactor(ui): migrate the caching, cost tracking, alerting and user detail forms to react-hook-form and shadcn

Moves the last of this lane's antd Form usage onto react-hook-form plus the
shadcn field kit, and takes the neutral greys in the files touched onto
semantic tokens so these screens are dark-mode ready.

Each unit is characterization-first: a payload-pinning test was written and
proven green against the antd original before any production code changed,
then re-run unedited against the migration. Every pre-existing test for these
files still passes without edits.

Two behaviour changes are deliberate and disclosed rather than buried.

Saving cache settings with the Advanced section collapsed used to drop
namespace, ttl, max_connections and the GCP fields from the payload, and to
send ssl as false even when the loaded value was true, because antd reports
only mounted fields at submit while its store keeps the rest. Keeping the
values in form state fixes that, and the payload no longer depends on whether
the section was expanded.

Adding a provider discount used to call the handler twice per click, because
the child submit button sat inside a Form carrying onFinish that called the
same function the button's onClick already called. Removing the leftover
wrapper collapses it to one request. Both calls read the same config and sent
the same body, so this changes request count rather than stored state.

* fix(ui): restore Enter submission on the provider discount form

Removing the antd Form wrapper from cost_tracking_settings also removed
native Enter submission from the Add Provider Discount modal, where the
original carried onFinish and AddProviderForm renders a type="submit"
button. Wrapping the fields in a native form whose onSubmit only calls
preventDefault restores it: implicit submission clicks the default
button, so Enter and a click each produce exactly one request rather
than the two the antd version fired on both paths.

The margin modal is deliberately left as a div. Its antd Form carried no
onFinish and AddMarginForm renders type="button", so Enter was already
inert there and a test now pins that alongside the working click path.

Also swaps five any[] mock forwarders for unknown[] in the user detail
test and asserts the role trigger renders its label rather than a blank
or raw value.
2026-08-18 21:04:44 +00:00
mateo
e67373304d chore(ui): regenerate schema.d.ts for ultrafast pricing fields
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-08-18 21:02:57 +00:00
Mateo Wang
69be083146
Merge pull request #37346 from BerriAI/litellm_lit_5755_client_side_timeout
fix(proxy): stop leaking the client_side_timeout marker to providers
2026-08-18 14:01:45 -07:00
Mateo Wang
3324122f45
Merge pull request #34445 from ayaangazali/litellm_azure_ai_strip_non_openai_message_fields
fix(azure_ai): strip non-OpenAI-spec message fields before request
2026-08-18 14:00:21 -07:00
mateo-berri
f8cc26a51f test(anthropic): pin one content_block_stop per tool_use block on the Responses adapter 2026-08-18 13:57:23 -07:00
mateo-berri
ec35098108 fix(main): forward store and prompt_cache_key on the MCP gateway early-return 2026-08-18 13:57:07 -07:00
mateo-berri
c1c23bf39a fix(proxy): reserve measured input tokens for multimodal project ITPM
Image, file, video, and previous_response_id requests reserved the whole
project ITPM limit up front, so any window with existing usage rejected
them and one in-flight multimodal request blocked the entire project.
Reserve the token_counter estimate instead, like every other request;
post-call reconciliation already charges actual usage.
2026-08-18 13:51:47 -07:00
mateo-berri
4e8efa041d fix(advisor): exclude in-sequence system rows from the advisor sub-call context 2026-08-18 13:51:01 -07:00
mateo-berri
39c5ccaed4 test(responses): inject a mocked http client instead of patching AsyncHTTPHandler.post 2026-08-18 13:45:48 -07:00
mateo-berri
76a2340685 test(router): drop docstrings from the new chained-proxy file upload tests 2026-08-18 13:45:36 -07:00
mateo
ac17352594 fix(cost_calculator): recognize the ultrafast service tier in cost calculation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-08-18 20:43:55 +00:00
Mateo Wang
035bd76669
Merge pull request #33767 from BerriAI/litellm_lit_4561_bedrock_passthrough_content_type
fix(proxy): forward Bedrock event-stream content-type on unbuffered passthrough
2026-08-18 13:43:47 -07:00
mateo-berri
e3a93c40be fix(proxy): stop leaking the client_side_timeout marker to providers 2026-08-18 13:37:07 -07:00
mateo-berri
89e563d3da fix(tinyfish): keep hidden-params header stashing within lint budgets 2026-08-18 13:37:03 -07:00
mateo-berri
93f08ed938 refactor(advisor): collapse router resolution to is_recognized_model plus wildcard check 2026-08-18 13:36:29 -07:00
KnyazSh
d7d2e440e0 Merge branch 'litellm_internal_staging' into feature/improve-gigachat-provider 2026-08-18 20:31:27 +00:00
mateo-berri
61625723a7 fix(responses): strip the responses/ routing prefix on the Responses API path
openai/responses/<model> deployments reached OpenAI as the literal model id
responses/<model> on /v1/responses and on /v1/messages (which rides the
Responses API for the openai provider) and 400ed with model_not_found, while
/v1/chat/completions already stripped the prefix. Strip a leading responses/
right after provider resolution so every Responses API entrypoint (HTTP,
websocket, compaction, the /v1/messages adapter) sends the real model id
2026-08-18 13:28:22 -07:00
mateo-berri
c6b40e9232 fix(azure_ai): keep the stripped message list and field tuple final 2026-08-18 13:28:11 -07:00
mateo-berri
c18d50b521 fix(batches): accept litellm_proxy in files and batches provider type literals 2026-08-18 13:28:06 -07:00
mateo-berri
8dc8cae0ec refactor(fireworks): name the Foundry deployment id prefix instead of commenting it 2026-08-18 13:17:44 -07:00
ryan-crabbe-berri
ceeab01b0d
refactor(ui): retire the tremor date range picker in favour of the shared advanced picker (#37302)
* refactor(ui): retire the tremor date range picker in favour of the shared advanced picker

UsageDatePicker was the last tremor DateRangePicker surface. Its three call sites in the old usage page and the caching dashboard now render AdvancedDatePicker, which already had the same prop interface, preset list and idle-callback day-boundary adjustment. AdvancedDatePicker drops its own tremor Button and Text for the shadcn Button and a plain paragraph, and it now applies the className prop it already declared so the mb-4 the tag-based usage tab passes keeps landing on the picker root. usage_date_picker.tsx and its calendar-grid test are removed, and the two no-restricted-imports suppressions those files carried are pruned

* fix(ui): let the advanced date picker anchor its panel to the trigger's left edge

The picker's dropdown is 600px wide and right-anchored to a 300px trigger, which was fine while every caller sat at the right edge of its row. The two old usage tabs place it in the left column, so the preset column landed left of the main scroll container and was clipped. AdvancedDatePicker gains an align prop (default right, unchanged for existing callers) and the old usage call sites pass left. The caching dashboard grid gives the picker an auto track instead of a third equal share, so the fixed-width trigger no longer spills past the card at laptop widths

* fix(ui): give the advanced date picker a real focusable trigger

The picker's display was a click-only div, so tabbing through the usage,
old usage, caching, cost optimization and guardrails monitor pages skipped
the date range control entirely and its focus ring classes never fired. It
is now a type="button" element carrying aria-expanded, which restores the
keyboard and screen reader access the tremor picker had. The panel also
reports its anchoring as data-align so the test can assert intent instead
of a Tailwind class

* fix(ui): make date picker relative-range presets keyboard-operable

The presets were non-focusable divs with click handlers, so a keyboard-only admin tabbed past Today / Last 7 days / Last 30 days / MTD / YTD and had to type both dates by hand. They are now buttons carrying aria-pressed.
2026-08-18 13:17:18 -07:00
mateo-berri
6bbc45ddaa Merge remote-tracking branch 'origin/litellm_internal_staging' into litellm_fix_chained_proxy_file_upload
# Conflicts:
#	litellm/router.py
2026-08-18 13:14:30 -07:00
mateo-berri
842bb7e917 Merge branch 'litellm_internal_staging' into feature/bedrock-mantle-quota-project-itr1 2026-08-18 13:14:14 -07:00
tin-berri
340d30867e
feat(ui): plan-mode override tier in the auto-router create and edit forms (#37319)
* feat(ui): plan-mode override tier in the auto-router create and edit forms

The backend plan_mode_min_tier field (#37230) was API-only. Both forms now
carry an Advanced: Plan-Mode Override panel in the shared complexity config
component: a toggle derived from field presence, so on writes the highest
tier that has models and off deletes the key, and a tier select limited to
tiers with models because the backend rejects a floor at an empty tier. The
edit modal manages the key on every save, so clearing it actually clears the
stored config instead of the preserved copy resurrecting it, while unmanaged
keys like plan_mode_patterns still round-trip untouched

* refactor(ui): hoist the eligible plan-mode tier list out of the panel JSX

* refactor(ui): move tierOptions into complexity_router_tiers, the shared tier-utility module
2026-08-18 13:13:21 -07:00
yuneng-jiang
00e1f25e9b
refactor(ui): migrate the login, onboarding and search tool forms to react-hook-form and shadcn (#37334)
* refactor(ui): migrate login, onboarding and search tool forms to react-hook-form and shadcn

Moves four forms off antd Form and Tremor widgets onto react-hook-form plus
the shadcn kit, and onto semantic colour tokens so the screens are dark-mode
ready. antd Modal and Alert stay as the shells.

The submit payload is unchanged in all four. Each unit is pinned by a
characterization test that was proven green against the antd original before
any production code changed, and the pre-existing test files pass unedited.

Extracts the search tool payload builder, which was duplicated verbatim
between the create and edit forms, into searchToolPayload.ts with unit tests,
and adds a shared PasswordInput so the four reveal toggles antd and Tremor
gave for free are preserved on one component.

* refactor(ui): keep the search tool Test Connection button an implicit submit

Tremor's Button renders no type attribute, so inside a form it defaults to
submit. The Test Connection button therefore fires both its own onClick and
the form's onFinish today, which creates the search tool as a side effect of
testing the connection. shadcn's Button renders type="button", so the naive
swap silently dropped that second path.

Restores parity with an explicit type="submit" and pins it with a test, so
the double submit is recorded rather than quietly changed. Fixing it belongs
in its own change.

Also prunes the two now-stale eslint suppression counts for the migrated
search tool files, scoped to those keys only.

* refactor(ui): announce the login button spinner the way antd did

antd's Button renders its loading indicator as role="img" with aria-label
"loading", so a screen reader announces the request in flight. The shadcn
spinner is a bare svg, which drops that. Labels it on the login button to
match, as already done on the onboarding submit button.

* fix(ui): drop noValidate from the migrated login, onboarding and search-tool forms

antd's Form renders no novalidate attribute and its required rules emit
aria-required rather than the native required attribute, so nothing in
these four forms was ever gated by native constraint validation. The only
type="email" input is disabled and readOnly, which bars it from validation
in every browser. Measured in jsdom and again in Chrome against a live
proxy: form.checkValidity() is true with the fields empty, a native submit
reaches react-hook-form, and zod blocks it with the same messages.

Removing the attribute keeps the rendered form faithful to antd, and keeps
a constraint added later behaving the way antd would have behaved instead
of being silently suppressed.

* fix(ui): accept a null api_key when seeding the search tool edit form

The list endpoint declares api_key as str | None and search_tool_info as
dict | None, and the masking helper returns non-string values untouched, so
a tool stored without an API key comes back as "api_key": null. zod's
optional() accepts undefined and rejects null, so the edit form for any
such tool failed with "expected string, received null" and could never be
submitted. antd carried no schema and forwarded whatever the server sent.

nullish() restores that, and the payload still forwards the null rather
than coercing it to an empty string. The new case seeds both null vectors
and fails without this change.

* chore(ui): drop the narration comments from the search tool forms

These restate the state change or the JSX block directly below them, which
the repo's comment policy rules out, and both files are rewritten by this
change rather than merely touched.
2026-08-18 13:12:27 -07:00
mateo-berri
7b60bd89c9 Merge remote-tracking branch 'origin/litellm_internal_staging' into litellm_pr34445_local 2026-08-18 13:09:41 -07:00
mateo-berri
0c5fcde883 Revert "feat(key_management): let any authenticated user resolve a raw key via /key/info"
This reverts commit d0c1d2be8a.
2026-08-18 13:08:28 -07:00
Mateo Wang
852368d72f
Merge pull request #37333 from BerriAI/litellm_lit_5726_auto_router_header_tags
fix(router): route Responses API input through the auto-router
2026-08-18 13:04:32 -07:00