Commit graph

37718 commits

Author SHA1 Message Date
user
22572eafaf
fix: merge admin metadata from both metadata and litellm_metadata
Greptile P2: _get_admin_metadata used 'litellm_metadata or metadata',
meaning a caller sending a non-empty litellm_metadata would shadow
admin config the proxy had injected into data['metadata']. Admin
exemptions would be silently ignored.

Check both keys and prefer whichever contains admin fields. Add
regression test covering the shadowing scenario.
2026-04-16 21:29:13 +00:00
user
1f50c6fa66
test: mock DNS resolution, hoist httpx import to module level
Greptile P1: six tests in test_url_utils.py performed real DNS
lookups to example.com, violating the tests/test_litellm/ mock-only
rule and risking offline CI failures. Add mock_dns_public and
mock_dns_failure fixtures that monkeypatch socket.getaddrinfo on
the url_utils module.

Greptile P2: move 'import httpx' from inside _extract_redirect_url
to module-level imports per CLAUDE.md style guide.
2026-04-16 21:28:13 +00:00
user
f5a9218cb3
chore: remove unused asyncio import 2026-04-16 21:08:07 +00:00
user
30c6556782
test: bypass SSRF validation in image handling tests 2026-04-16 21:08:06 +00:00
user
1ba2be77ae
refactor: move url_utils to litellm_core_utils to avoid proxy dependency
SDK core modules (image_handling, token_counter) should not import
from litellm.proxy. Move url_utils.py to litellm_core_utils/ so
bare SDK installs without proxy dependencies still work.
2026-04-16 21:07:04 +00:00
user
00b25d6ca4
fix: sync redirect bypass, Host header port, redirect loop dead code
Pass follow_redirects through in HTTPHandler.get() — previously the
parameter was accepted but never forwarded to the underlying httpx
client, making sync redirect protection ineffective.

Include port in Host header when non-default (e.g. example.com:8080).

Fix redirect loop to read Location header directly instead of
response.next_request (which is None when follow_redirects=False).
2026-04-16 21:07:04 +00:00
user
e2a0c96663
fix: redirect loop was dead code, clean up imports
Read Location header directly instead of response.next_request (which
is None when follow_redirects=False). Resolve relative redirect URLs
with httpx.URL.join(). Remove unused imports.
2026-04-16 21:07:04 +00:00
user
814d03d1ce
fix: fail-closed on unparseable IPs, rewrite HTTPS when SSL verify disabled
_is_blocked_ip now returns True (blocked) for unparseable addresses
instead of False (allowed). HTTPS URLs are rewritten to validated IPs
when ssl_verify is disabled, closing the DNS rebinding window that
exists without TLS certificate binding.
2026-04-16 21:07:04 +00:00
user
62ec396775
test: mock SSRF validation in openapi spec URL test 2026-04-16 21:07:03 +00:00
user
b94aaa72b0
fix: skip DNS resolution for base64 data in token counter, add unit tests
Check URL scheme before calling safe_get in token counter to avoid
unnecessary DNS resolution on base64-encoded image data.

Add 14 unit tests for validate_url covering blocked networks, scheme
validation, URL rewriting, and DNS failure handling.
2026-04-16 21:07:03 +00:00
user
037fb573f7
fix: preserve caller headers across redirect hops in safe_get 2026-04-16 21:07:03 +00:00
user
d15196b519
fix(proxy): add safe_get/async_safe_get with redirect validation
Add safe_get() and async_safe_get() helpers that validate each
redirect hop before following. For HTTPS, rely on TLS certificate
binding instead of URL rewriting. Simplify call sites to use the
new helpers.
2026-04-16 21:07:03 +00:00
user
9363f36481
fix(proxy): add SSRF protection via resolve-and-rewrite for user-supplied URLs
Add validate_url() utility that resolves DNS once, validates all IPs
against private network ranges, and rewrites the URL to connect to the
validated IP directly. Prevents DNS rebinding by pinning to the resolved
IP. Disable follow_redirects to prevent redirect-based SSRF bypasses.

Applied to all user-supplied URL entry points:
- Image URL fetching in chat completions
- Token counter image dimension fetching
- RAG file ingestion
- MCP OpenAPI spec loading
2026-04-16 21:07:03 +00:00
user
413f89892b
test: update dynamic callback params test for turn_off_message_logging removal
Verify turn_off_message_logging is no longer extracted from request
kwargs since it is now admin-only.
2026-04-16 21:07:00 +00:00
user
34e9be1ba7
fix: merge team metadata in admin helper, remove turn_off_message_logging from dynamic params
Include user_api_key_team_metadata alongside user_api_key_metadata in
_get_admin_metadata() so team-level guardrail settings are respected.
Key-level settings take precedence over team-level.

Remove turn_off_message_logging from _supported_callback_params so it
cannot be set via request metadata. Admin controls logging globally
or via key/team configuration.

Update tests to verify user-injected guardrail flags are ignored while
admin-configured flags are respected.
2026-04-16 21:06:59 +00:00
user
3cd5796fc7
refactor: extract admin metadata helper, hoist loop-invariant tag resolution
Extract _get_admin_metadata() in CustomGuardrail to deduplicate metadata
lookup. Hoist tag resolution above the deployment loop in budget limiter.
Update stale comment in tag routing.
2026-04-16 21:06:59 +00:00
user
74a49b527c
fix(proxy): read guardrail config from admin metadata, fix tag routing consistency
Read guardrail control flags (disable_global_guardrails, opted_out_global_guardrails)
from admin-configured key metadata instead of the request body. This ensures
callers cannot override admin security policies.

Fix tag-based routing to enforce strict tag checks regardless of whether the
request includes tags. Fix budget limiter to use the same dynamic metadata
key resolution as the tag router for consistent tag extraction.
2026-04-16 21:06:59 +00:00
user
815a2bed1a
test: add regression tests for cross-org admin escalation
Verify that an org admin of org-A cannot operate on org-B, and that
an admin of both orgs can operate on both.
2026-04-16 21:06:56 +00:00
user
91bfbe6efe
fix(proxy): enforce organization boundaries in admin operations
Validate org admin role against all requested organizations instead
of returning on first match. Scope team list queries to the caller's
permitted organizations when filtering by user_id.
2026-04-16 21:06:56 +00:00
Ryan Crabbe
260679679f
fix(ui): repair router_settings tests broken by full antd mock
The antd mocks in RouterSettingsForm.test.tsx and index.test.tsx
replaced the entire antd module with only Select, so the Switch and
Button used by nested components failed to render. Use importOriginal
to preserve the rest of antd and override only Select.

Also fix the TagFilteringToggle click assertion — antd's Switch fires
onChange with (checked, event), so toHaveBeenCalledWith(true) was
always going to miss. Assert the checked arg directly instead of
coupling to antd's call signature.
2026-04-16 14:04:33 -07:00
Ryan Crabbe
f796036af0
feat(proxy): add --reload flag for uvicorn hot reload (dev only)
Opt-in CLI flag, off by default, no env var. Only affects the uvicorn
run path; gunicorn/hypercorn paths and prod (which doesn't pass the
flag) are unaffected.
2026-04-16 13:52:39 -07:00
shin-berri
7279dca929
Merge pull request #25898 from BerriAI/litellm_llmTranslationOomMitigation_staging
[Infra] Reduce llm_translation_testing parallelism and tolerate worker restarts
2026-04-16 13:31:05 -07:00
Yuneng Jiang
ebac729146
[Infra] CI: reduce llm_translation_testing parallelism and tolerate worker restarts
Workers in llm_translation_testing have been crashing mid-run with
"Not properly terminated" (OOM), even after bumping resource_class to
xlarge. Reduce xdist workers from 8 to 4 to lower peak memory, and add
--max-worker-restart=5 so a crashed worker is replaced instead of
failing the whole run.
2026-04-16 13:10:22 -07:00
ishaan-berri
c0fc4c4234
Merge pull request #25876 from BerriAI/litellm_hotfix_opus_4.7
Some checks are pending
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
CodSpeed Benchmarks / benchmarks (push) Waiting to run
Helm unit test / unit-test (push) Waiting to run
Read Version from pyproject.toml / read-version (push) Waiting to run
Scorecard supply-chain security / Scorecard analysis (push) Waiting to run
Unit Tests: Proxy DB Operations / proxy-db (auth-checks, tests/proxy_unit_tests/test_auth_checks.py tests/proxy_unit_tests/test_user_api_key_auth.py, 20, 8) (push) Waiting to run
Unit Tests: Proxy DB Operations / proxy-db (key-generation, tests/proxy_unit_tests/test_key_generate_prisma.py, 30, 0) (push) Waiting to run
Unit Tests: Proxy DB Operations / proxy-db (remaining, tests/proxy_unit_tests --ignore=tests/proxy_unit_tests/test_key_generate_prisma.py --ignore=tests/proxy_unit_tests/test_auth_checks.py --ignore=tests/proxy_unit_tests/test_user_api_key_auth.py, 30, 8) (push) Waiting to run
Unit Tests: Security / security (push) Waiting to run
GitHub Actions Security Analysis / zizmor (push) Waiting to run
Litellm hotfix opus 4.7
2026-04-16 12:19:00 -07:00
shin-berri
65717add14
Merge pull request #25887 from BerriAI/litellm_/vigilant-cannon
[Infra] Bump llm_translation_testing resource class to xlarge
2026-04-16 11:53:52 -07:00
Yuneng Jiang
72ba880905
[Infra] Bump llm_translation_testing resource class to xlarge 2026-04-16 11:50:55 -07:00
Ryan Crabbe
ff982bb376
fix: return None for routing_strategy_args when not latency-based
When the routing strategy is not latency-based, get_settings() returned
{} for routing_strategy_args. Empty objects are truthy in JS, so the
frontend fallback defaults (ttl: 3600, lowest_latency_buffer: 0) were
skipped, resulting in an empty Latency-Based Configuration section.

Return None instead so the frontend || fallback works as designed.
2026-04-16 11:37:27 -07:00
Ryan Crabbe
72be35f9b8
chore(ui): migrate router_settings page from Tremor to antd
Replace @tremor/react components with antd equivalents:
- Button → antd Button
- TextInput → antd Input
- Switch → antd Switch
2026-04-16 11:01:30 -07:00
Ryan Crabbe
5aba1841cc
Extract shared PKCE helpers into src/utils/pkce.ts
Deduplicates base64UrlEncode, generateCodeVerifier, and
generateCodeChallenge which were copy-pasted across useMcpOAuthFlow
and useUserMcpOAuthFlow hooks.
2026-04-16 10:35:52 -07:00
Sameer Kankute
c6c970ca43
Merge pull request #25875 from BerriAI/litellm_docs_opus_4.7
Fix version in docs
2026-04-16 22:53:14 +05:30
Sameer Kankute
fe6fef97d1
Fix version in docs 2026-04-16 22:50:17 +05:30
ishaan-berri
6fab790a6e
Merge pull request #25867 from BerriAI/litellm_day_0_opus_4.7_support
Litellm day 0 opus 4.7 support
2026-04-16 22:49:51 +05:30
yuneng-jiang
21c0718850
Merge pull request #25871 from BerriAI/litellm_yj_apr15
[Infra] Merge dev branch
2026-04-16 10:11:48 -07:00
Sameer Kankute
13522ff33a
Fix version in docs 2026-04-16 22:41:32 +05:30
Yuneng Jiang
073685136d
bump: version 0.4.65 → 0.4.66 2026-04-16 09:54:56 -07:00
Yuneng Jiang
b80bd9d523
bump: version 1.83.8 → 1.83.9 2026-04-16 09:48:26 -07:00
ishaan-berri
44c992416c
Merge pull request #25867 from BerriAI/litellm_day_0_opus_4.7_support
Litellm day 0 opus 4.7 support
2026-04-16 09:42:11 -07:00
Yuneng Jiang
b26f858ab0
fix(ci): authorize langgraph-prebuilt in liccheck.ini
langgraph-prebuilt was previously pulled in as a transitive of langgraph
so PyPI license metadata was reported as unknown. Now that it is
explicitly pinned (==1.0.8) to avoid the broken 1.0.9 release, the
license checker flags it. It is published under MIT by the same
langchain-ai/langgraph repository as langgraph itself.
2026-04-16 09:41:51 -07:00
Yuneng Jiang
c294bbe4f0
fix(deps): pin langgraph-prebuilt==1.0.8 to avoid broken 1.0.9
langgraph-prebuilt 1.0.9 imports ExecutionInfo and ServerInfo from
langgraph.runtime, but those symbols are not exported until
langgraph 1.1.0. Our pin of langgraph==1.0.10 allows
langgraph-prebuilt<1.1.0,>=1.0.8, and uv resolves to 1.0.9 (the
latest in range), which breaks at import time in every test that
touches langgraph.prebuilt (e.g. tests/pass_through_tests/test_mcp_routes.py):

  ImportError: cannot import name 'ExecutionInfo' from 'langgraph.runtime'

Pinning langgraph-prebuilt to 1.0.8 pairs correctly with
langgraph==1.0.10 and restores the import path.
2026-04-16 09:36:05 -07:00
Sameer Kankute
07d863b8e7
Remove max support for opus 4.7 2026-04-16 21:58:03 +05:30
Sameer Kankute
f94c8dda82
Fix model names 2026-04-16 21:47:58 +05:30
Yuneng Jiang
dafa1bf97c
Merge remote-tracking branch 'origin/litellm_internal_staging' into litellm_yj_apr15
# Conflicts:
#	litellm/litellm_core_utils/litellm_logging.py
#	uv.lock
2026-04-16 09:17:20 -07:00
Sameer Kankute
b3d5ff5774
Fix tests + add docs 2026-04-16 21:45:31 +05:30
Sameer Kankute
a9ff4c6991
Fix add leagcy support for claude code 2026-04-16 21:20:48 +05:30
Sameer Kankute
607412defb
feat(bedrock): inject thinking for clear_thinking context_management on Messages API
Bedrock rejects clear_thinking_20251015 unless thinking is enabled or adaptive.
Inject minimal extended thinking and interleaved-thinking beta when Claude Code
sends context_management without thinking. Adds unit tests.

Made-with: Cursor
2026-04-16 21:11:09 +05:30
Sameer Kankute
fb33daa09f
opus 4.7 doesn't support tool search 2026-04-16 21:11:07 +05:30
Sameer Kankute
0868a82c34
Add support for opus 4.7 with new effort levels 2026-04-16 20:45:45 +05:30
Sameer Kankute
26937a2146
Merge pull request #25831 from BerriAI/litellm_oss_staging_04_15_2026_p1
litellm oss staging 04/15/2026
2026-04-16 19:53:00 +05:30
Sameer Kankute
4b5c86b8a1
Fix code qa 2026-04-16 19:29:08 +05:30
Sameer Kankute
baf19b4413
Fix import error 2026-04-16 19:16:49 +05:30