mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-09 03:18:44 +00:00
* fix(vector_stores): stop leaking stored credentials in direct search debug logs Direct vector store providers (RESP datastores like Valkey) have no HTTP request to echo, so both search handlers called `logging_obj.pre_call` with no `api_base`. The logging helper treats an empty `api_base` as "nothing to render" and falls back to `str(self.model_call_details)`, which carries the resolved `litellm_params`: the stored `valkey_password` and the embedding config's `api_key` among them. The stdout logger's regex redaction hid this, but `pre_call` also writes the same string to `litellm_params["metadata"]["raw_request"]`, which ships unredacted to every logging callback (Langfuse, OTel, etc.). Pass a synthetic `<provider>://<vector_store_id>` endpoint plus an explicit `request_str` so the debug output describes the call instead of dumping call details, and fold the duplicated sync/async blocks into one helper so the sanitized descriptor cannot drift between them. * fix(vector_stores): type direct search query as Sequence[str] The new helper's list[str] annotation pushed LIT001 over its type-discipline ceiling. Sequence is the read-only shape the helper actually needs, and list[str] still satisfies it at both call sites. |
||
|---|---|---|
| .. | ||
| test_aiohttp_cleanup_closed.py | ||
| test_aiohttp_handler.py | ||
| test_aiohttp_so_keepalive.py | ||
| test_aiohttp_transport.py | ||
| test_async_client_cleanup.py | ||
| test_credential_leak_prevention.py | ||
| test_gemini_session_leak.py | ||
| test_http_handler.py | ||
| test_llm_http_handler.py | ||
| test_mock_transport.py | ||