mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-10 03:28:53 +00:00
The ownership check on the Responses API only ran when the id arrived in the proxy's own encrypted format. An id in any other shape skipped the check and was forwarded upstream, so a key that did not own the response could retrieve, cancel, delete, or chain off it. Every addressed id now goes through one authorization step shared by retrieve, cancel, delete, list-input-items, and create's previous_response_id. An id the proxy did not issue is refused with 403 unless the deployment opts in with general_settings.allow_unmanaged_response_ids, has responses id security disabled, has no signing key configured, or the caller is a proxy admin. |
||
|---|---|---|
| .. | ||
| litellm-dashboard | ||
| Dockerfile | ||
| nginx.conf | ||