- proxy_server.py: disable allow_credentials when allow_origins=['*'] (wildcard
+ credentials is a browser security misconfiguration). Add LITELLM_CORS_ORIGINS
env var to configure explicit allowed origins.
- create_views.py: narrow broad 'except Exception' to only catch genuine
'view does not exist' errors; re-raise all other DB errors (auth, connection,
etc.) that were previously silently swallowed.
- spend_log_cleanup.py: validate execute_raw() return type is int before using
it as a deletion count; break loop safely on unexpected types to prevent
infinite deletion loops.
- Only release distributed lock in finally if it was actually acquired;
prevents spurious Redis release_lock calls on early returns
- Treat bare integer maximum_spend_logs_retention_period as days (e.g. 3 → "3d")
instead of silently failing with a ValueError
- Elevate "Skipping cleanup" log from info to error so misconfigured
retention settings are visible without verbose logging
- Add tests for all three fixes
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix: Add support for GOOGLE_API_KEY environment variables for Gemini API authentication
* added test cases
* incoperated feedback to make it more maintainable
* fix failed linting CI