Commit graph

37969 commits

Author SHA1 Message Date
Julio Quinteros Pro
597f88dade
Merge pull request #22002 from jquinter/fix/flaky-rpm-limit-test
fix: atomic RPM rate limiting in model rate limit check
2026-02-28 14:05:34 -03:00
Julio Quinteros Pro
62d2bf25e7
Merge pull request #22328 from BerriAI/fix/ruff-plr0915-too-many-statements
fix(lint): suppress PLR0915 in complex transform methods
2026-02-28 14:04:24 -03:00
Cesar Garcia
c3bb1cb10c
Merge pull request #22405 from Chesars/fix/scan-duplicate-issues-env
fix(ci): remove duplicate env key in scan_duplicate_issues workflow
2026-02-28 13:48:17 -03:00
Shivaang
7c4e576400 fix: add API key validation in OpenRouter image edit config
Raise ValueError when OPENROUTER_API_KEY is not set instead of
sending "Bearer None" and getting a confusing 401 from the API.
2026-02-28 11:44:32 -05:00
Chesars
10a91c5199 fix(ci): remove duplicate env key in scan_duplicate_issues workflow
The greptile suggestion in #22034 was applied without removing the
original env block, leaving a duplicate env key that makes the YAML
invalid. GitHub fails to parse the workflow on every push to main,
creating failed run entries ("No jobs were run").
2026-02-28 13:27:59 -03:00
Shivaang
3775ba3eaa feat(openrouter): add image edit support for OpenRouter models
OpenRouter supports image editing through its chat completions endpoint
for models like google/gemini-2.5-flash-image, but LiteLLM raised
ValueError("image edit is not supported for openrouter") because
OpenRouter was not registered as an image edit provider.

Add OpenRouterImageEditConfig that routes image edit requests through
the chat completions endpoint with the source image as a base64 data
URL in the message content array.

Fixes https://github.com/BerriAI/litellm/issues/22305
2026-02-28 11:22:54 -05:00
Cesar Garcia
7f5c8653f0
Merge pull request #18478 from Chesars/fix/prevent-scheduled-workflow-in-forks
fix: update_price_and_context_window workflow from running in forks
2026-02-28 13:10:15 -03:00
Harshit28j
99210e9867 fix req changes 2026-02-28 21:32:57 +05:30
Julio Quinteros Pro
d7340b595b
Update .github/workflows/codeql.yml
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-28 12:16:42 -03:00
Harshit Jain
e1d09a17b7
Merge pull request #22283 from BerriAI/litellm_presidio_stream_v3
Litellm presidio stream v3
2026-02-28 20:13:48 +05:30
Julio Quinteros Pro
53f3123030 fix(ci): add custom CodeQL workflow to replace expensive default setup
The default CodeQL setup runs all 45 Python security queries against the
entire codebase. Two queries (CleartextLogging, PolynomialReDoS) produce
result sets > 2 GiB, causing 49+ minute runs that fail and block CI.

- Add custom workflow with 30-minute timeout and concurrency limits
- Exclude py/clear-text-logging-sensitive-data (CWE-312)
- Exclude py/polynomial-redos (CWE-730)
- Skip scanning tests/, docs/, and UI build output

NOTE: The Default Setup must be disabled in repo Settings > Code security
before merging, otherwise both will run simultaneously.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 11:40:22 -03:00
Harshit Jain
1c9ecd4ec6
Merge pull request #22384 from BerriAI/litellm_aws_edge_case
Litellm aws edge case
2026-02-28 19:52:55 +05:30
Harshit28j
1073ba6d13 fix req changes 2026-02-28 19:06:31 +05:30
Harshit28j
1badececa3 fix: presidio req change 2026-02-28 18:53:37 +05:30
Chesars
8a85a2cf82 Merge branch 'litellm_oss_staging_02_27_2026' of https://github.com/BerriAI/litellm into litellm_oss_staging_02_27_2026 2026-02-28 09:54:56 -03:00
Julio Quinteros Pro
df99be904c
Merge pull request #22034 from BerriAI/feat/duplicate-issues-bot
feat(ci): add duplicate issue detection and auto-close bot
2026-02-28 09:28:27 -03:00
Harshit28j
83cab3f54a Rewrite test to exercise actual failure_handler code path
Replace simulated test with one that invokes the real
Logging.failure_handler(), mocks LangFuseHandler to capture kwargs,
and asserts original_response is excluded and session_id is preserved.
This ensures the test catches regressions if the production code changes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 17:47:25 +05:30
Harshit28j
315b00fd19 Fix Langfuse failure path kwargs and add session_id trace tests
Fix: The Langfuse failure logging path was passing self.model_call_details
(which includes original_response, potentially a coroutine) instead of the
clean local kwargs copy. This aligns the failure path with the success path
behavior (litellm_logging.py:2956).

Reverted the session_id-as-trace_id approach as it causes trace collisions
in Langfuse (multiple calls in the same session would overwrite each other).
Instead, session_id is correctly used only for Langfuse session grouping via
trace_params["session_id"], while each call retains its own unique trace_id.

Added 4 tests:
- session_id correctly passed as trace session_id (not trace_id)
- session_id preserved for ERROR level (failure) logs
- explicit trace_id takes priority over session_id
- failure path kwargs excludes original_response

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 17:34:59 +05:30
Harshit Jain
bfdea4227a
Merge pull request #22103 from Harshit28j/litellm_feat_datadog_metrics
feat: ability to trace metrics datadog
2026-02-28 17:25:23 +05:30
Harshit28j
7e9930cc3b Fix Langfuse trace_id mapping for failed logs and prioritize session_id
This fix addresses Bug 1 where failed LiteLLM logs were using request_id instead of session_id for Langfuse trace mapping, breaking trace correlation.

Changes:
1. Fix kwargs inconsistency in failure path (litellm_logging.py:2956)
   - Changed from passing self.model_call_details to passing local kwargs variable
   - Matches success path behavior and excludes original_response (potentially a coroutine)

2. Prioritize session_id as trace_id fallback (langfuse.py:607-615)
   - When no explicit trace_id is provided, now uses session_id from metadata
   - This ensures traces with the same session_id are grouped together in Langfuse
   - Maintains backward compatibility: only activates when session_id is set

Testing:
- All 28 existing Langfuse tests pass (excluding pre-existing test_langfuse_e2e_sync which fails due to missing API key)
- Specifically verified trace_id resolution tests still pass

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-28 17:22:01 +05:30
Harshit Jain
09b557f861
Merge pull request #22385 from BerriAI/litellm_security_release_notes
Doc: security vulnerability scan report to v1.81.14 release notes
2026-02-28 16:35:57 +05:30
Harshit28j
b39218059a fix req change 2026-02-28 16:34:23 +05:30
Harshit Jain
24aa8bac09
fix req changes test case 2026-02-28 16:31:05 +05:30
Harshit Jain
539f2eeba4
Update litellm/proxy/management_endpoints/key_management_endpoints.py
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-28 16:28:32 +05:30
Harshit28j
dee2a62686 Add security vulnerability scan report to v1.81.14 release notes 2026-02-28 16:13:45 +05:30
Harshit28j
0b7d8b9a0d fix: edge case when key alias empty 2026-02-28 16:05:55 +05:30
David Velarde
29d1d0479f
[Feature] Add Gemini 3.1 Flash Image Preview input and output cost details 2026-02-28 11:09:38 +01:00
David Velarde
dcfd25e1f1
[Feature] Add Gemini 3.1 Flash Image Preview pricing details 2026-02-28 10:56:38 +01:00
Harshit Jain
290ecf88f8
Merge branch 'main' of https://github.com/BerriAI/litellm 2026-02-28 15:24:00 +05:30
Harshit Jain
1576033495
Merge pull request #22299 from BerriAI/litellm_health_check_tokens
Litellm health check tokens
2026-02-28 15:05:45 +05:30
Harshit28j
e0168db683 add docs and formatting 2026-02-28 14:08:09 +05:30
yuneng-jiang
8abba63b48
Merge pull request #22373 from BerriAI/litellm_ui_project_keys
[Feature] UI - Projects: Add project keys table and project dropdown to key create/edit
2026-02-28 00:15:31 -08:00
Harshit28j
465adce872 feat reaq changes 2026-02-28 13:40:53 +05:30
yuneng-jiang
b914c98562 [Feature] UI - Projects: Add project key table, project dropdown on key create/edit
Add project_id support across the key management UI:
- Project details page now shows a paginated key table with search
- Key create form includes a project dropdown that locks team selection
- Key edit/info views display project as read-only
- Beta alert banner on Projects page

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-28 00:04:06 -08:00
Harshit28j
9dc085694c feat: jwt mapping vkeyv 2026-02-28 13:29:46 +05:30
yuneng-jiang
a4b7a93a37
Merge pull request #22360 from BerriAI/litellm_ui_project_info
[Feature] UI - Projects: Add Project Details Page
2026-02-27 22:11:13 -08:00
yuneng-jiang
50dc7b520c
Update ui/litellm-dashboard/src/components/Projects/ProjectModals/CreateProjectModal.tsx
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-27 22:11:04 -08:00
yuneng-jiang
c4b21fab06
Merge pull request #22356 from BerriAI/litellm_key_list_filters
[Feature] Key list endpoint: Add project_id and access_group_id filters
2026-02-27 22:09:54 -08:00
yuneng-jiang
061703abc0 [Feature] UI - Projects: Add Project Details page with Edit modal
- Add ProjectDetailsPage with header, details card, spend/budget progress,
  model spend bar chart, keys placeholder, and team info card
- Refactor CreateProjectModal into base form pattern (ProjectBaseForm)
  shared between Create and Edit flows
- Add EditProjectModal with pre-filled form data from backend
- Add useProjectDetails and useUpdateProject hooks
- Add duplicate key validation for model limits and metadata
- Wire project ID click in table to navigate to detail view
- Move pagination inline with search bar

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-27 21:35:21 -08:00
yuneng-jiang
6d8b5b75ce [Feature] Key list endpoint: Add project_id and access_group_id filters
Add filtering capabilities to /key/list endpoint for project_id and access_group_id parameters. Both filters work globally across all visibility rules and stack with existing sort/pagination params. Added comprehensive unit tests for the new filters.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-27 21:25:44 -08:00
yuneng-jiang
85590e4538
Merge pull request #22354 from BerriAI/litellm_cost_tracking_vitest
[Test] UI - CostTrackingSettings: Add comprehensive Vitest coverage
2026-02-27 21:24:02 -08:00
yuneng-jiang
c4a0174e00 test: add comprehensive Vitest coverage for CostTrackingSettings
Add 88 tests across 9 test files for the CostTrackingSettings component directory:
- provider_display_helpers.test.ts: 9 tests for helper functions
- how_it_works.test.tsx: 9 tests for discount calculator component
- add_provider_form.test.tsx: 7 tests for provider form validation
- add_margin_form.test.tsx: 9 tests for margin form with type toggle
- provider_discount_table.test.tsx: 12 tests for table editing and interactions
- provider_margin_table.test.tsx: 13 tests for margin table with sorting
- use_discount_config.test.ts: 11 tests for discount hook logic
- use_margin_config.test.ts: 12 tests for margin hook logic
- cost_tracking_settings.test.tsx: 15 tests for main component and role-based rendering

All tests passing. Coverage includes form validation, user interactions, API calls, state management, and conditional rendering.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-27 21:16:41 -08:00
Ishaan Jaff
9f2453712e
perf: streaming latency improvements — 4 targeted hot-path fixes (#22346)
* perf: raise aiohttp connection pool limits (300→1000, 50/host→500)

* perf: skip model_copy() on every chunk — only copy usage-bearing chunks

* perf: replace list+join O(n²) with str+= O(n) in async_data_generator

* perf: cache model-level guardrail lookup per request, not per chunk
2026-02-27 20:45:53 -08:00
Ishaan Jaff
ee703cea99
fix(jwt): OIDC discovery URLs, roles array handling, dot-notation error hints (#22336)
* fix(jwt): support OIDC discovery URLs, handle roles array, improve error hints

Three fixes for Azure AD JWT auth:

1. OIDC discovery URL support - JWT_PUBLIC_KEY_URL can now be set to
   .well-known/openid-configuration endpoints. The proxy fetches the
   discovery doc, extracts jwks_uri, and caches it.

2. Handle roles claim as array - when team_id_jwt_field points to a list
   (e.g. AAD's "roles": ["team1"]), auto-unwrap the first element instead
   of crashing with 'unhashable type: list'.

3. Better error hint for dot-notation indexing - when team_id_jwt_field is
   set to "roles.0" or "roles[0]", the 401 error now explains to use
   "roles" instead and that LiteLLM auto-unwraps lists.

* Add integration demo script for JWT auth fixes (OIDC discovery, array roles, dot-notation hints)

Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>

* Add demo_servers.py for manual JWT auth testing with mock JWKS/OIDC endpoints

Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>

* Add demo screenshots for PR comment

Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>

* Add integration test results with screenshots for PR review

Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>

* address greptile review feedback (greploop iteration 1)

- fix: add HTTP status code check in _resolve_jwks_url before parsing JSON
- fix: remove misleading bracket-notation hint from debug log (get_nested_value does not support it)

* Update tests/test_litellm/proxy/auth/test_handle_jwt.py

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

* remove demo scripts and assets

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-27 20:30:47 -08:00
Julio Quinteros Pro
8ab542875c
Merge pull request #21107 from BerriAI/fix/bedrock-filter-json-tool-call-scoped
fix(bedrock): filter internal json_tool_call when mixed with real tools
2026-02-28 01:17:09 -03:00
Ishaan Jaff
eea083fa4b
fix(mcp): default available_on_public_internet to true (#22331)
* fix(mcp): default available_on_public_internet to true

MCPs were defaulting to private (available_on_public_internet=false) which
was a breaking change. This reverts the default to public (true) across:
- Pydantic models (AddMCPServerRequest, UpdateMCPServerRequest, LiteLLM_MCPServerTable)
- Prisma schema @default
- mcp_server_manager.py YAML config + DB loading fallbacks
- UI form initialValue and setFieldValue defaults

* fix(ui): add forceRender to Collapse.Panel so toggle defaults render correctly

Ant Design's Collapse.Panel lazy-renders children by default. Without
forceRender, the Form.Item for 'Available on Public Internet' isn't
mounted when the useEffect fires form.setFieldValue, causing the Switch
to visually show OFF even though the intended default is true.

Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>

* fix(mcp): update remaining schema copies and MCPServer type default to true

Missed in previous commit per Greptile review:
- schema.prisma (root)
- litellm-proxy-extras/litellm_proxy_extras/schema.prisma
- litellm/types/mcp_server/mcp_server_manager.py MCPServer class

* ui(mcp): reframe network access as 'Internal network only' restriction

Replace scary 'Available on Public Internet' toggle with 'Internal network only'
opt-in restriction. Toggle OFF (default) = all networks allowed. Toggle ON =
restricted to internal network only. Auth is always required either way.

- MCPPermissionManagement: new label/tooltip/description, invert display via
  getValueProps/getValueFromEvent so underlying available_on_public_internet
  value is unchanged
- mcp_server_view: 'Public' → 'All networks', 'Internal' → 'Internal only' (orange)
- mcp_server_columns: same badge updates

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Ishaan Jaff <ishaan-jaff@users.noreply.github.com>
2026-02-27 20:06:07 -08:00
rasmi
bffce842a1
Remove Apache 2 license from SKILL.md (#22322) 2026-02-27 19:33:55 -08:00
Julio Quinteros Pro
9db4ab1188
Merge pull request #22039 from demoray/bcaswell/fix-long-path-filenames
fix: shorten guardrail benchmark result filenames for Windows long path support
2026-02-28 00:28:34 -03:00
Brian Caswell
bcf9acf5ea Update litellm/proxy/guardrails/guardrail_hooks/litellm_content_filter/guardrail_benchmarks/test_eval.py
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-28 00:27:39 -03:00
Brian Caswell
37ec9f8995 fix: shorten guardrail benchmark result filenames for Windows long path support
Fixes #21941

The generated result filenames from _save_confusion_results contained
parentheses, dots, and full yaml filenames, producing paths that exceed
the Windows 260-char MAX_PATH limit. Rework the safe_label logic to
produce short {topic}_{method_abbrev} filenames (e.g. insults_cf.json)
while preserving the full label inside the JSON content.

Rename existing tracked result files to match the new naming convention.
2026-02-28 00:27:39 -03:00