Commit graph

31762 commits

Author SHA1 Message Date
Varun Chawla
d0163941b2
fix(proxy): add regression tests for #20441 - <script> tags in messages (#20573)
* fix: empty guardrails/policies arrays should not trigger enterprise license check (#20304)

The UI sends empty arrays for enterprise-only fields (guardrails, policies,
logging) even when the user has not configured these features. The backend
`is not None` check treated `[]` as a truthy intent to use the feature,
falsely requiring an enterprise license for basic team operations.

Backend: Add `and updated_kv[field] != [] and updated_kv[field] != {}`
guards in `_update_metadata_fields` so empty collections are skipped.

UI: Conditionally omit guardrails, logging, and policies from the
payload when empty instead of defaulting to `[]`.

Fixes #20304

* fix: allow clearing fields with empty collections while skipping enterprise check

Address PR review feedback:

1. Move the empty-collection guard into _update_metadata_field (singular)
   so that empty lists/dicts skip only the premium license check but still
   get written into metadata. This lets users intentionally clear a
   previously-set field (e.g. guardrails: []) without being blocked, while
   the UI's default empty arrays still don't trigger a false enterprise
   error.

2. Remove sys.path hack from test file; use standard imports that work
   with pytest discovery.

3. Add tests verifying that empty collections are moved into metadata
   (field clearing works) even though they bypass the premium check.

Fixes #20304

* fix(proxy): add regression tests for #20441 - ensure <script> tags in LLM messages are not blocked

The 403 Forbidden error when sending messages containing `<script>` is caused
by external WAF/reverse proxy infrastructure (confirmed by the standard nginx
HTML 403 response format), not by LiteLLM's own content filtering. However,
these regression tests ensure that:

1. The content filter guardrail's built-in patterns do not match HTML tags
2. Messages containing <script> and other HTML tags pass through the content
   filter unchanged when no explicit HTML-blocking rules are configured
3. The HTTP request body parser correctly handles JSON payloads containing
   HTML content without modification

These tests guard against accidentally introducing HTML/XSS filtering that
would break legitimate LLM API usage (e.g., discussing HTML/JavaScript code).

Closes #20441

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-06 23:21:00 -08:00
Piotr Grabowski
3114eb336e
fix(openrouter): fix crash of gpt-5.2-codex by using mode "chat" (#20577)
Commit 1cdda28b6 changed "openrouter/openai/gpt-5.2-codex" to mode "responses",
but this broke GPT-5.2-Codex with OpenRouter:

```
response = await litellm.acompletion(
            model="openrouter/openai/gpt-5.2-codex",
            messages=[{"role": "user", "content": "Hello"}],
            api_key=os.environ.get("OPENROUTER_API_KEY"),
)
```
crashes with: `OpenrouterException - argument of type 'NoneType' is not iterable`

Responses API is in beta in OpenRouter and no other OpenRouter models use "responses"
mode. The commit that changed this probably did it by mistake.

Therefore change the mode to "chat" and fix the crash.
2026-02-06 23:17:04 -08:00
Varun Chawla
405bb4b7b6
fix(responses): handle Pydantic ValidationError when provider omits required fields in streaming events (#20580)
When an OpenAI-compatible upstream provider emits minimal streaming event
payloads that omit required fields (e.g. created_at, output, output_index,
content_index), Pydantic raises a ValidationError crashing the SSE stream
and returning HTTP 500.

Fall back to model_construct() on ValidationError, consistent with the
existing pattern in transform_response_api_response for non-streaming.

Fixes https://github.com/BerriAI/litellm/issues/20570

Signed-off-by: Varun Chawla <varun_6april@hotmail.com>
2026-02-06 23:14:11 -08:00
Simon Sadedin
0a55571f75
[Feat] add au version of claude-opus-4-6 to model cost map (#20566)
Notes: General support for Opus 4.6 was added in #20506 however
it omitted the AU (australian) specific instance profile used
in Bedrock. This change only adds the the au id. It is copied
from the US model settings which is consistent with past
additions of this regional model profile.
2026-02-06 16:06:33 -08:00
michelligabriele
f4a0b80a25
fix(sso): extract user roles from JWT access token for Keycloak compatibility (#20591)
Keycloak (and similar OIDC providers) include role claims in the JWT
access token but not in the UserInfo endpoint response. Previously,
roles were only extracted from UserInfo, causing all SSO users to
default to internal_user_view_only regardless of their actual role.

Changes:
- Extract user roles from JWT access token in process_sso_jwt_access_token()
  when UserInfo doesn't provide them (tries role_mappings first, then
  GENERIC_USER_ROLE_ATTRIBUTE)
- Handle list-type role values in get_litellm_user_role() since Keycloak
  returns roles as arrays (e.g. ["proxy_admin"] instead of "proxy_admin")
- Add 9 new unit tests covering role extraction and list handling
- Update 3 existing tests for new JWT decode behavior

Closes #20407
2026-02-06 16:05:51 -08:00
yuneng-jiang
218373c427
Merge pull request #20205 from BerriAI/litellm_router_search_fix
[Re-issue: Fix] Keys and Teams Router Setting + Allow Override of Router Settings
2026-02-06 15:42:22 -08:00
yuneng-jiang
fd3ca081cc use cached keys and teams for router settings 2026-02-06 15:07:29 -08:00
Ishaan Jaff
b78f4c924c
[Fix] A2a Agent Gateway Fixes - A2A agents deployed with localhost/internal URLs in their agent cards (e.g., http://0.0.0.0:8001/) (#20604)
* v1 card resolver fix

* fix: is_localhost_or_internal_url

* fix code

* test_fix_agent_card_url_replaces_localhost

* test restruct

* test_a2a_non_streaming

* test agnts

* add exception handling

* init errors

* add localhost retry

* add agent_testing

* test_a2a_non_streaming

* _build_streaming_logging_obj

* code qa fixes

* test_card_resolver_fallback_from_new_to_old_path

* fix linting
2026-02-06 15:02:34 -08:00
michelligabriele
6a213fc3bc
fix(mcp): resolve OAuth2 'Capabilities: none' bug for upstream MCP servers (#20602)
- process_mcp_request() now falls back to OAuth2 passthrough when Authorization header contains a non-LiteLLM token (catches HTTPException and ProxyException 401/403)
- MCPClient._get_auth_headers() adds missing MCPAuth.oauth2 case
2026-02-06 15:00:35 -08:00
yuneng-jiang
400e560ee5 Merge remote-tracking branch 'origin' into litellm_router_search_fix 2026-02-06 14:08:55 -08:00
yuneng-jiang
a4689c9b22
Merge pull request #20549 from swayambhu94/fix/ui/antd-notification
refactor: migrate Ant Design notifications to use `App.useApp()` cont…
2026-02-06 13:15:37 -08:00
yuneng-jiang
dfc4a1b412
Merge pull request #20599 from BerriAI/litellm_model_page_col_resize
[Fix] UI - Model Page: Column Resizing on Smaller Screens
2026-02-06 12:38:01 -08:00
yuneng-jiang
ac8f3807db
Merge pull request #20462 from BerriAI/litellm_model_info_cost
[Fix] UI - Model Info Page: Fix Input and Output Labels
2026-02-06 12:34:34 -08:00
yuneng-jiang
4de0ed7a9e
Merge pull request #20444 from BerriAI/litellm_ui_config_req_auth_mh
[Feature] UI - Admin Settings: Add option for Authentication for public AI Hub
2026-02-06 12:34:27 -08:00
yuneng-jiang
49eab29335
Merge pull request #20596 from BerriAI/litellm_ui_yj_cov_01
[Infra] UI - Testing: Adding Unit Testing Coverage
2026-02-06 12:33:40 -08:00
yuneng-jiang
8df6cfe9d8 fix model page col resize 2026-02-06 12:27:03 -08:00
Alexsander Hamir
5733f6213b
Add INFO-level session reuse logging per request (#20597)
- Log when shared aiohttp session is attached to each request
- Log when no shared session is available
- Visible at INFO level (production-safe)
2026-02-06 11:36:33 -08:00
yuneng-jiang
ee70010ef1 Adding testing coverage 2026-02-06 11:32:35 -08:00
yuneng-jiang
b859d76cc2
Merge pull request #20553 from BerriAI/litellm_team_soft_budget_email
[Feature] Team Soft Budget Email Alerts
2026-02-06 09:36:16 -08:00
Alexsander Hamir
09fb6d0087
Warn when budget lookup fails; cache won't populate (#20545)
* Warn when budget lookup fails; cache won't populate

- Add _log_budget_lookup_failure helper in auth_checks.py
- Log at WARNING in get_user_object, get_team_object, get_key_object
  when DB lookups fail (schema mismatch, etc.)
- Add schema migration hint for prisma/db errors
- Add dry-run test for _log_budget_lookup_failure

* fix: skip budget lookup failure log for expected user-not-found case

Avoid logging 'cache will not be populated' when the user simply doesn't
exist - not caching is correct behavior in that case. Only log for
unexpected errors (schema, DB, etc.) where the message is meaningful.
2026-02-06 09:24:44 -08:00
Alexsander Hamir
53a1f2d21c
perf(prometheus): parallelize budget metrics, fix caching bug, reduce CPU by ~40% (#20544) 2026-02-06 09:18:24 -08:00
Sameer Kankute
ad1282de82
Merge pull request #20551 from BerriAI/litellm_opus_4.6_thinking
Add full support  for Opus 4.6 (Anthropic, Azure AI, Bedrock, Vertex AI)
2026-02-06 19:30:47 +05:30
Sameer Kankute
eab7a99800
Merge pull request #20578 from BerriAI/litellm_claude_code_beta_headers
Add unsupported claude code beta headers in json
2026-02-06 19:10:13 +05:30
Sameer Kankute
285b2d2a12 add context_management header for compact_20260112 for messages 2026-02-06 19:06:49 +05:30
Sameer Kankute
db8423b799 Fix: test_json_response_nested_json_schema 2026-02-06 18:52:04 +05:30
Sameer Kankute
2e0715bd61 Fix mypy issue 2026-02-06 18:45:54 +05:30
Sameer Kankute
05ce4c68e5 Fix: test_vertex_ai_partner_models_anthropic_remove_prompt_caching_scope_beta_header 2026-02-06 18:34:57 +05:30
Sameer Kankute
fa26c6eeec fix mypy issue 2026-02-06 18:29:28 +05:30
Sameer Kankute
40ff79655c Add not_available in inference_geo 2026-02-06 18:29:28 +05:30
Sameer Kankute
786bd6ebc0 Fix merge conflicts 2026-02-06 18:29:14 +05:30
Sameer Kankute
c1a43914ee Add documentation related to new beta header json 2026-02-06 17:54:56 +05:30
Sameer Kankute
3f9a7b1956 Add update_headers_with_filtered_beta in all messages API providers 2026-02-06 17:45:45 +05:30
Sameer Kankute
25a19b2091 Add update_headers_with_filtered_beta in anthropic 2026-02-06 17:45:05 +05:30
Sameer Kankute
920fea9520 feat: Add Unsupported Anthropic beta headers for each provider json 2026-02-06 17:44:09 +05:30
Swayambhu
a48a8ec945 refactor: Directly use Ant Design's notification hook instead of App.useApp for notification management. 2026-02-06 15:35:11 +05:30
Sameer Kankute
bfd21b5e00
Merge branch 'main' into litellm_opus_4.6_thinking 2026-02-06 14:17:40 +05:30
Sameer Kankute
d07c87860d
Merge pull request #20514 from PeterDaveHelloKitchen/feat/add-claude-opus-4-6-model
Align Claude Opus 4.6 metadata and limits
2026-02-06 14:14:52 +05:30
Sameer Kankute
a2b29d6328 Add complete documentation for claude_opus_4_6 2026-02-06 14:04:39 +05:30
Sameer Kankute
1ec89b8a04 Feat: add inference_geo based pricing 2026-02-06 13:58:47 +05:30
Sameer Kankute
0934a4ab68 Correct litellm/litellm/llms/anthropic/chat/transformation.py 2026-02-06 13:08:43 +05:30
Sameer Kankute
358a081f63 Add compaction support for vertex ai 2026-02-06 12:52:28 +05:30
Sameer Kankute
1396813d74 The compact beta feature is not currently supported on the Converse and ConverseStream APIs 2026-02-06 12:52:28 +05:30
Sameer Kankute
d0444f402c Add test for compaction in anthropic 2026-02-06 12:52:28 +05:30
Sameer Kankute
7a473f2954
Apply suggestion from @greptile-apps[bot]
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-06 12:07:13 +05:30
Sameer Kankute
ea518a7684
Apply suggestion from @greptile-apps[bot]
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-06 12:06:50 +05:30
Sameer Kankute
887a977ab4 Add doc on how to enable compaction via chat completion 2026-02-06 12:05:36 +05:30
Sameer Kankute
24dda99bd7 Handle compaction block in the input request 2026-02-06 11:55:12 +05:30
Sameer Kankute
c03ba8394e Add compaction block in provider spcific fields streaming+ non streaming 2026-02-06 11:54:47 +05:30
Sameer Kankute
039b37fac1 Add compaction type block in the output 2026-02-06 11:31:35 +05:30
yuneng-jiang
0cb79ace97 Fixing tests 2026-02-05 21:44:00 -08:00