mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-09 03:18:44 +00:00
These fields pick which server-side secret is read and where the resulting assertion is sent, so a team admin who can otherwise manage a team-scoped deployment must not be able to set them. The create, update and patch model paths and both credential write paths now reject them for anyone below proxy admin, mirroring the existing blocked-flag gate. The field list is derived from anthropic_wif_litellm_params rather than copied, so a new federation field is covered the day it is added Also fixes two things CI caught: credential_values_to_delete is a PATCH instruction rather than part of the credential, so it stays out of dumps that feed config loading and the Prisma write, and the provider discovery route is registered in the backend allowlist |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| allowlist.py | ||