Commit graph

36164 commits

Author SHA1 Message Date
yuneng-jiang
7356bf1e48 address greptile review feedback (greploop iteration 2)
- storageUtils: replace deprecated escape()/unescape() with
  TextEncoder/TextDecoder for UTF-8 base64 encoding
- chatHistory: use setObfuscated/getObfuscated consistently across
  ChatUI.tsx, useChatHistory.ts, and tests
- Tests updated and passing (39/39)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 23:23:43 -07:00
yuneng-jiang
d5bad2f53e address greptile review feedback (greploop iteration 1)
- storageUtils: fix btoa() crash on non-Latin1 chars by encoding through
  encodeURIComponent before base64
- sanitizeImageSrc: restrict data: URIs to image/* and application/pdf
- useMcpOAuthFlow: restore console.warn on storage failure, document
  localStorage migration fallback removal timeline
- ChatUI: add comment explaining chatHistory persistence origin

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 23:06:42 -07:00
yuneng-jiang
065e7b45e1 fix(ui): resolve remaining CodeQL security findings
- sanitizeImageSrc: use URL parsing to return parsed.href instead of the
  raw input string, breaking the taint chain for CodeQL's xss-through-dom
- handleImageUpload: sanitize blob URLs at creation time before storing
- LoginPage: validate SSO code format with a regex guard so CodeQL no
  longer flags the user-controlled-bypass

CodeQL javascript-security-extended now reports zero findings.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 23:02:20 -07:00
yuneng-jiang
473118d88d fix(ui): validate return URL before redirect to prevent open redirect
Port security fix from litellm_security_fixes_v1.82.3: use
isValidReturnUrl() guard and reconstruct a safe path from parsed URL
components before calling window.location.replace().

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 22:29:35 -07:00
yuneng-jiang
97b37ca174 fix(ui): address CodeQL security alerts from GHAS scan
- Incomplete string escaping: add backslash escaping before quote
  escaping in TeamGuardrailsTab, CodeSnippets; use regex /g flag in
  public_model_hub wildcard replace
- Clear-text storage: obfuscate sensitive sessionStorage values
  (API keys, OAuth state, MCP form state) via base64 encoding through
  new storageUtils helper
- XSS-through-DOM: add sanitizeImageSrc helper to validate image src
  URLs use safe schemes (blob:, data:, http:, https:) before rendering

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 22:27:13 -07:00
yuneng-jiang
d67a549669
Merge pull request #24470 from BerriAI/litellm_ui_unit_tests_five_components
[Test] UI: Add unit tests for 5 untested dashboard components
2026-03-23 21:54:11 -07:00
yuneng-jiang
5d9136bb71 [Test] UI: Add unit tests for 5 untested dashboard components
Add Vitest + RTL unit tests for WorkerDropdown, AccessGroupSelector,
MemberTable, ModelSelector, and AutoRotationView (37 tests total).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-23 21:33:12 -07:00
Krish Dholakia
3292d02aa4
Merge pull request #24460 from DmitriyAlergant/ci/skip-scheduled-workflows-on-forks
ci: skip scheduled workflows on forks
2026-03-23 19:54:50 -07:00
Krish Dholakia
14fffc2770
Merge pull request #24432 from BerriAI/krrishdholakia/project-id-tracking
feat(proxy): add project_alias tracking in callbacks
2026-03-23 19:24:44 -07:00
DmitriyAlergant
1310a275d2 ci: narrow codeql guard to schedule-only
Use event_name check so push/PR-triggered CodeQL scans still run on
forks — only the scheduled run is skipped.
2026-03-23 21:39:11 -04:00
DmitriyAlergant
91bc095e18 ci: skip scheduled workflows on forks
Add `if: github.repository == 'BerriAI/litellm'` guard to scheduled
jobs in stale.yml, codeql.yml, and create_daily_staging_branch.yml.

This matches the existing pattern in auto_update_price_and_context_window.yml
and prevents these workflows from running unnecessarily on fork repositories.
2026-03-23 21:29:00 -04:00
Krrish Dholakia
26d162ccf4 fix(test): add user_api_key_project_alias to spend logs expected keys
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-23 18:12:50 -07:00
Krrish Dholakia
742e176611 docs(reasoning_content.md): update guide 2026-03-23 17:23:14 -07:00
Krish Dholakia
8a3aa4d31c
Merge pull request #24434 from BerriAI/krrishdholakia/prometheus-spend-metadata
feat(prometheus): include spend_logs_metadata in custom labels
2026-03-23 16:52:59 -07:00
Krrish Dholakia
dd0e7dcca8 test(prometheus): add tests for spend_logs_metadata in custom labels
Verify that spend_logs_metadata is correctly merged into combined_metadata
and flows through to Prometheus custom labels. Tests cover: basic extraction,
precedence when keys overlap, all three metadata sources combined, and None
handling.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-23 11:02:21 -07:00
Krrish Dholakia
7fa623df91 feat(prometheus): include spend_logs_metadata in custom labels
Add spend_logs_metadata to combined_metadata in Prometheus logger so
custom metadata from x-litellm-spend-logs-metadata header can be used
in Prometheus custom labels.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-23 10:59:18 -07:00
Krrish Dholakia
6809213957 feat(proxy): add project_alias tracking through callback metadata pipeline
Thread project_alias alongside project_id through the metadata pipeline so
callbacks receive the human-readable project name. DRY up duplicate metadata
dict construction in proxy_track_cost_callback and pass_through_endpoints by
reusing get_sanitized_user_information_from_key — future metadata fields only
need adding in one place.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-23 10:44:17 -07:00
Krish Dholakia
63425b4cb4
Merge pull request #23910 from michelligabriele/fix/guardrail-post-call-logging
fix(proxy): post-call guardrail response not captured for logging
2026-03-23 09:21:28 -07:00
michelligabriele
fa7ccf0893 fix(test): add request_data param to test mock + black formatting 2026-03-23 15:43:05 +01:00
michelligabriele
9a231bd758 fix(proxy): use real request_data in Responses API streaming fallback path 2026-03-23 15:39:23 +01:00
michelligabriele
4625ccbaa2 fix(proxy): anchor metadata dict in _process_response/_process_error so pop() mutates the real dict 2026-03-23 15:39:23 +01:00
michelligabriele
d8fd9a20ed fix(proxy): address Greptile review — streaming request_data, OCR backward compat, test coverage
- Pass request_data to end-of-stream process_output_streaming_response call
- Restore inputs.update() in OCR handler for third-party guardrail providers
- Add streaming end-to-end test for guardrail logging passthrough
2026-03-23 15:39:23 +01:00
michelligabriele
ae454fd700 fix(proxy): OpenAI Moderation post-call guardrail response not captured for logging
Two independent bugs prevented post-call OpenAI Moderation guardrail
results from reaching downstream logging callbacks (Langfuse, Datadog).

Bug 1: process_output_response() created a throwaway request_data dict,
so guardrail info written by @log_guardrail_information was discarded.
Fixed by threading the real request_data from the unified guardrail
dispatcher through all 13 BaseTranslation handlers, with litellm_metadata
injection preserved for third-party guardrails (Zscaler, Prompt Security).
Also extended to process_output_streaming_response for consistency.

Bug 2: The @log_guardrail_information decorator collapsed the full
moderation API response (categories, scores, flagged status) to "allow".
Fixed by overriding _process_response/_process_error on
OpenAIModerationGuardrail to stash and log the full response, following
the established Model Armor pattern.
2026-03-23 15:39:22 +01:00
yuneng-jiang
c89496f378
Merge pull request #24342 from BerriAI/litellm_yj_march_21_2026
[Fix] UI - Teams: Table refresh, infinite dropdown, leftnav migration
2026-03-21 23:36:21 -07:00
yuneng-jiang
38d477507d remove outdated e2e test 2026-03-21 23:14:53 -07:00
yuneng-jiang
6bb08883af adding poetry lock 2026-03-21 23:01:28 -07:00
yuneng-jiang
fa65433c8c bump: version 1.82.5 → 1.82.6 2026-03-21 22:56:09 -07:00
yuneng-jiang
d91980dc45 adding build 2026-03-21 22:55:04 -07:00
yuneng-jiang
071c8641de bump: version 0.4.59 → 0.4.60 2026-03-21 22:54:41 -07:00
yuneng-jiang
88a4c7aeaf bump: version 0.4.58 → 0.4.59 2026-03-21 22:54:38 -07:00
yuneng-jiang
34d079910b chore: update Next.js build artifacts (2026-03-22 05:53 UTC, node v22.16.0) 2026-03-21 22:53:50 -07:00
yuneng-jiang
9073daeebc [Fix] UI - TeamDropdown: Match org dropdown styling and fix test mock
- Use Select.Option with font-medium alias + Text secondary ID to match OrganizationDropdown
- Default page size to 20
- Add useInfiniteTeams mock to AddModelForm tests

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 22:52:16 -07:00
yuneng-jiang
aea8e32048 [Fix] UI: Team table refresh, infinite team dropdown, leftnav for dashboard routes
- OldTeams: refresh table via fetchTeamsV2 after team create instead of appending
- TeamDropdown: rewrite with useInfiniteTeams for paginated fetch, scroll-to-load, and debounced search
- Update all TeamDropdown consumers to use the new self-fetching API
- Dashboard layout: switch from Sidebar2 to SidebarProvider (leftnav)
- Leftnav: add MIGRATED_PAGES routing for path-based navigation (api-reference)
- Navbar: remove chat button

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 22:05:26 -07:00
yuneng-jiang
9963b31e07 Revert "fix(proxy): restore per-entity breakdown in aggregated daily activity endpoint"
This reverts commit 9c3fab24ad.
2026-03-21 21:37:29 -07:00
yuneng-jiang
f5194b5ce3
Merge pull request #24334 from BerriAI/litellm_yj_march_21_2026
[Infra] Build UI for release
2026-03-21 18:03:38 -07:00
yuneng-jiang
d217e49193 chore: update Next.js build artifacts (2026-03-22 01:02 UTC, node v22.16.0) 2026-03-21 18:02:32 -07:00
yuneng-jiang
e3d4c29d37
Merge pull request #24323 from BerriAI/litellm_ryan_march_20
litellm ryan march 20
2026-03-21 15:57:28 -07:00
Ryan Crabbe
3e27ff1b78 fix: resolve mypy type errors in audit_logs.py 2026-03-21 15:42:01 -07:00
Ryan Crabbe
f494ab513f docs: add High Availability Control Plane documentation
New docs page covering the HA control plane architecture where each
worker instance has its own DB, Redis, and master key. Includes a
React component diagram, setup configs, SSO notes, and local testing
instructions.
2026-03-21 15:31:49 -07:00
yuneng-jiang
1986f1034e
Merge pull request #24211 from BerriAI/litellm_dev_sameer_16_march_week
Litellm dev sameer 16 march week
2026-03-21 15:19:15 -07:00
yuneng-jiang
72fba093c8 Merge remote-tracking branch 'origin/main' into litellm_dev_sameer_16_march_week 2026-03-21 15:11:29 -07:00
yuneng-jiang
7b31ea40a9
Merge pull request #22844 from BerriAI/litellm_oss_staging_03_05_2026
Litellm oss staging 03 05 2026
2026-03-21 15:09:48 -07:00
Ryan Crabbe
9b90e80f71 fix: resolve mypy type errors in audit_logs.py
Extract multiline `or` chain from LiteLLM_AuditLogs constructor to fix
pydantic mypy plugin field-type misattribution, and add explicit
Optional[bool] annotation to avoid variable name shadowing conflict.
2026-03-21 15:08:47 -07:00
yuneng-jiang
c6bb7a5be5 Apply Black formatting to 11 files
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:05:53 -07:00
yuneng-jiang
e3b62c0915 fix: apply Black formatting to 6 files after main merge
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:03:06 -07:00
yuneng-jiang
2b889f1627
Merge pull request #23471 from michelligabriele/fix/aggregated-activity-entity-breakdown
fix(proxy): restore per-entity breakdown in aggregated daily activity endpoint
2026-03-21 14:59:41 -07:00
yuneng-jiang
10b0139bf8
Merge branch 'main' into litellm_oss_staging_03_05_2026 2026-03-21 14:58:11 -07:00
Krish Dholakia
f911d8d865
Merge pull request #23818 from BerriAI/litellm_oss_staging_03_17_2026
fix(fireworks): skip #transform=inline for base64 data URLs (#23729)
2026-03-21 14:54:39 -07:00
Krrish Dholakia
cb4027531b fix: add explicit "summary" not in result guards to opt-out test paths
Addresses Greptile feedback that test assertions were weakened when
removing summary: "detailed" expectations — now every default-behavior
test explicitly asserts that "summary" is absent from the result.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 14:53:25 -07:00
yuneng-jiang
35316e115f fix: apply Black formatting to 7 files
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 14:51:15 -07:00