mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-10 03:28:53 +00:00
When forward_headers=True on a generic pass_through_endpoint, the proxy's own Authorization header (carrying the LiteLLM master/virtual key) was forwarded verbatim to the upstream provider, and x-pass- prefixed headers leaked through with the prefix intact alongside the stripped version. Root cause: forward_headers_from_request only stripped content-length and host before merging request headers into the outbound set. Auth headers (authorization, api-key, x-api-key, x-goog-api-key) and x-pass- prefixed headers were included raw. Fix: strip all _PASS_THROUGH_PROTECTED_HEADERS and x-pass- prefixed headers from request_headers before the merge. x-pass- entries are snapshotted first so the prefix-stripping loop still processes them. Also removes authorization and x-api-key from the WebSocket passthrough forwarding allowlist (same leak vector). Fixes #32202 Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| llm_provider_handlers | ||
| test_carry_guardrail_logging_info.py | ||
| test_llm_pass_through_endpoints.py | ||
| test_method_specific_routing.py | ||
| test_pass_through_endpoints.py | ||
| test_passthrough_auth_default.py | ||
| test_passthrough_endpoints_common_utils.py | ||
| test_passthrough_guardrail_block_otel_span.py | ||
| test_passthrough_guardrails.py | ||
| test_passthrough_guardrails_field_targeting.py | ||
| test_passthrough_post_call_guardrails.py | ||
| test_streaming_handler_interrupt.py | ||
| test_vertex_ai_batch_passthrough.py | ||
| test_vertex_passthrough_load_balancing.py | ||
| test_watsonx_proxy_route.py | ||