mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-29 01:42:19 +00:00
* refactor(messages): take the provider client from the injected HTTP pool The messages route kept its own process-wide reqwest client, so it ignored ssl_verify, CA bundles, client certs, proxies and every other setting that litellm-http resolves. The machine now takes the HttpClientPool and the call's HttpClientConfig, as OCR does, and the bridge passes its shared pool. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(http): hand out an owned Client and move chat, audio and OIDC onto the pool HttpClientPool now returns litellm_http::Client, a newtype only crates/http can build, so every provider client carries the resolved TLS, proxy and timeout settings. Chat completions and audio transcription drop their process-wide reqwest clients and take the pool and call config like messages; their 600s ceiling moves to the request. OidcResolver takes its client instead of building one, and the bridge hands it the pooled one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(secrets): build Google, Azure and CyberArk manager clients from the pool The native secret managers built bare reqwest clients, so they ignored the host's TLS and proxy settings. load_native_manager now takes the pool and the host config and hands each manager a pooled client. CyberArk's CYBERARK_SSL_VERIFY and CYBERARK_CLIENT_CERT/KEY become an override on the host config instead of a hand-built client. To express a certificate and key in separate files, HttpClientConfig::client_certificate is now a ClientIdentity that is either one PEM or a split pair. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(clippy): only crates/http may build a reqwest client Fence reqwest::Client, ClientBuilder and the TLS builder methods with disallowed-types and disallowed-methods so new code takes a litellm_http::Client from the pool. crates/http is exempt as the one place clients are built, and testkit as a dev-only installer. Tests move to litellm_http::Client::plain_for_test or a pooled client. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(secrets-cyberark): keep verifying certificates when the host disables it Python hands CyberArk its own ssl_verify, which wins over the global setting, so CYBERARK_SSL_VERIFY unset or true still verifies even when the host sets ssl_verify false. The pooled client copied the host's Disabled and would send the API key unverified; fall back to the built-in roots instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(python-bridge): treat a missing litellm package as no host HTTP settings Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Yujong Lee <yujong@berri.ai> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
106 lines
3.5 KiB
Rust
106 lines
3.5 KiB
Rust
#![cfg(feature = "azure")]
|
|
|
|
#[tokio::test]
|
|
async fn azure_handler_reads_missing_and_failed_secrets() {
|
|
use litellm_secrets::{
|
|
Error, KeyManagementSettings, KeyManagementSystem, SecretManager, azure::AzureKeyVault,
|
|
get_secret_from_manager,
|
|
};
|
|
use wiremock::{
|
|
Mock, MockServer, ResponseTemplate,
|
|
matchers::{path, query_param},
|
|
};
|
|
|
|
let server = MockServer::start().await;
|
|
Mock::given(path("/secrets/KEY"))
|
|
.and(query_param("api-version", "7.4"))
|
|
.respond_with(
|
|
ResponseTemplate::new(200).set_body_json(serde_json::json!({"value": "value"})),
|
|
)
|
|
.expect(1)
|
|
.mount(&server)
|
|
.await;
|
|
let manager = SecretManager::AzureKeyVault(
|
|
AzureKeyVault::with_client(
|
|
litellm_http::Client::plain_for_test(),
|
|
server.uri().parse().unwrap(),
|
|
std::sync::Arc::new(|name: &str| (name == "AZURE_AD_TOKEN").then(|| "fake".to_owned())),
|
|
)
|
|
.unwrap(),
|
|
);
|
|
assert_eq!(manager.system(), KeyManagementSystem::AzureKeyVault);
|
|
let settings = KeyManagementSettings::default();
|
|
let value = get_secret_from_manager(&manager, "KEY", &settings, &|_: &str| None)
|
|
.await
|
|
.unwrap()
|
|
.unwrap();
|
|
assert_eq!(value.as_str(), Some("value"));
|
|
|
|
let not_found = Mock::given(path("/secrets/MISSING"))
|
|
.respond_with(ResponseTemplate::new(404))
|
|
.expect(1)
|
|
.mount_as_scoped(&server)
|
|
.await;
|
|
assert_eq!(
|
|
get_secret_from_manager(&manager, "MISSING", &settings, &|_: &str| None)
|
|
.await
|
|
.unwrap(),
|
|
None
|
|
);
|
|
drop(not_found);
|
|
|
|
Mock::given(path("/secrets/FAILED"))
|
|
.respond_with(ResponseTemplate::new(500))
|
|
.expect(1)
|
|
.mount(&server)
|
|
.await;
|
|
assert!(matches!(
|
|
get_secret_from_manager(&manager, "FAILED", &settings, &|_: &str| None).await,
|
|
Err(Error::Azure(_))
|
|
));
|
|
}
|
|
|
|
#[rstest::rstest]
|
|
#[case::null(serde_json::json!({"value":null}))]
|
|
#[case::absent(serde_json::json!({}))]
|
|
#[case::empty(serde_json::json!({"value":""}))]
|
|
#[tokio::test]
|
|
async fn successful_azure_responses_do_not_fall_back_when_the_value_is_empty_or_null(
|
|
#[case] body: serde_json::Value,
|
|
) {
|
|
use litellm_secrets::{
|
|
OidcResolver, SecretManager, SecretManagerState, SecretResolver, SecretValue,
|
|
azure::AzureKeyVault,
|
|
};
|
|
use std::sync::Arc;
|
|
use wiremock::{Mock, MockServer, ResponseTemplate, matchers::any};
|
|
let server = MockServer::start().await;
|
|
Mock::given(any())
|
|
.respond_with(ResponseTemplate::new(200).set_body_json(body.clone()))
|
|
.expect(1)
|
|
.mount(&server)
|
|
.await;
|
|
let manager = AzureKeyVault::with_client(
|
|
litellm_http::Client::plain_for_test(),
|
|
server.uri().parse().unwrap(),
|
|
Arc::new(|name: &str| (name == "AZURE_AD_TOKEN").then(|| "token".into())),
|
|
)
|
|
.unwrap();
|
|
let resolver = SecretResolver::new_python_compatible(
|
|
Arc::new(SecretManagerState::new(
|
|
SecretManager::AzureKeyVault(manager),
|
|
Default::default(),
|
|
)),
|
|
Arc::new(|_: &str| Some("environment".into())),
|
|
OidcResolver::new(litellm_http::Client::plain_for_test()),
|
|
);
|
|
assert_eq!(
|
|
resolver
|
|
.get_secret_str("KEY", Some(SecretValue::new("default")))
|
|
.await
|
|
.unwrap()
|
|
.as_ref()
|
|
.map(SecretValue::expose),
|
|
body.get("value").and_then(serde_json::Value::as_str)
|
|
);
|
|
}
|