litellm/tests
Aldrich_CC 477ca5b0d0 fix(proxy): redact SHA-256 token hash from 429 error body (#27884)
The parallel request limiter previously rendered the offending virtual
key's full 64-char SHA-256 hash verbatim into the customer-facing
``detail`` field of every 429 response, e.g.

    {"error":{"message":"Rate limit exceeded for api_key: \
523544f141d47ff188ff366337ddd3c9b44968b565d83a1c9b6fa56c543d3042. ..."}}

The hash cannot be reversed to recover the raw ``sk-...`` secret, but
exposing it in an HTTP error body is still a real downside:

* lets a third party fingerprint which key is hitting limits across
  customers;
* discloses LiteLLM's internal key-storage strategy
  (SHA-256-of-raw-key) to anyone watching error bodies;
* violates the principle of least information for an error surface
  that customers / integrators read.

``redact_user_api_key_info=True`` does not cover this path — that flag
only applies to Langfuse callback metadata and a few logging surfaces,
not the rate-limit response shape (see GH #27884 for the user report).

This patch adds a small ``_sanitize_descriptor_value_for_response``
static helper. When the offending descriptor is ``api_key``, the
customer-facing detail now reads:

    Rate limit exceeded for api_key: sk-...3d3042. Limit type: ...

— keeping the last 6 hex chars so an operator reading both the 429
body and the structured proxy log (which still includes the full hash
at debug level) can correlate, but no longer round-tripping the full
identifier. Non-key descriptors (``user_id`` / ``team_id`` / ``model``)
flow through untouched — those are user-supplied scoping values, not
key material.

A ``verbose_proxy_logger.debug`` call preserves the full descriptor
for operator-side correlation; that log is gated by the proxy's debug
flag and never reaches the customer.

Closes #27884.

Test plan
---------
* Added ``test_429_body_does_not_leak_full_api_key_hash`` — integration
  test through ``async_pre_call_hook`` that asserts the 64-char hash
  is absent from the response detail, the redacted form preserves the
  last-6 correlation suffix, and the ``sk-...`` prefix signals the
  redaction.
* Added ``test_sanitize_descriptor_value_redacts_api_key`` — unit test
  that the sanitiser leaves non-key descriptors alone and tolerates
  the ``unknown`` fallback emitted when the resolver can't find a
  matching descriptor.
* Existing ``test_missing_descriptor_fallback`` and
  ``test_multiple_rate_limits_per_descriptor`` continue to pass
  (they assert on substring prefixes, not the hash value).

Test results
------------
``pytest tests/test_litellm/proxy/hooks/test_parallel_request_limiter_v3.py``
runs 51 passed + 1 skipped (the pre-existing skip), 13 warnings.
2026-05-16 03:55:18 +08:00
..
agent_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
audio_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
basic_proxy_startup_tests build: migrate packaging, CI, and Docker from Poetry to uv (#25007) 2026-04-09 11:46:23 -07:00
batches_tests fix(vertex-ai): fix zero cost/usage on completed Vertex AI batch jobs (#27912) 2026-05-15 04:47:02 -07:00
benchmarks Add CodSpeed performance benchmarks (#23676) 2026-03-14 18:44:36 -07:00
code_coverage_tests feat(audio_transcription): add NVIDIA Riva STT provider (#27185) 2026-05-05 17:17:51 -07:00
documentation_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
enterprise fix(tests): use canonical litellm_enterprise import path (#27699) 2026-05-12 12:32:57 -07:00
guardrails_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
image_gen_tests Merge pull request #27795 from BerriAI/litellm_vcr-cache-observability-and-fixes-c5bc 2026-05-14 13:51:16 -07:00
litellm Add new chat model metadata (#27313) 2026-05-06 15:15:21 -07:00
litellm-proxy-extras style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
litellm_core_utils Merge branch 'litellm_internal_staging' into litellm_staging_03_22_2026 2026-04-20 19:56:00 +05:30
litellm_utils_tests Merge pull request #27795 from BerriAI/litellm_vcr-cache-observability-and-fixes-c5bc 2026-05-14 13:51:16 -07:00
llm_responses_api_testing test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
llm_translation fix(vcr): aggregate worker stats on the controller so the session summary actually renders under xdist 2026-05-13 07:24:32 +00:00
load_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
local_testing test(vcr): drop dead 'from respx import MockRouter' imports 2026-05-13 00:32:03 +00:00
logging_callback_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
mcp_tests feat: litellm shin agent oss staging 05 10 2026 (#27631) 2026-05-11 20:31:43 -07:00
multi_instance_e2e_tests
ocr_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
old_proxy_tests/tests fix: cleanup tests 2026-03-30 16:24:35 -07:00
openai_endpoints_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
otel_tests fix(tests): swap dall-e to gpt-image-1 after openai deprecation 2026-05-12 16:55:18 -07:00
pass_through_tests chore(deps): refresh dependency locks 2026-05-04 11:36:18 -07:00
pass_through_unit_tests test(vcr): mark Bedrock prompt-caching cross-call tests VCR-incompatible 2026-05-13 01:19:03 +00:00
proxy_admin_ui_tests chore(deps): refresh dependency locks 2026-05-04 11:36:18 -07:00
proxy_e2e_anthropic_messages_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
proxy_security_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
proxy_unit_tests fix(managed_batches): convert raw output_file_id to managed ID in CheckBatchCost poller (#27984) 2026-05-15 04:41:38 -07:00
router_unit_tests Merge pull request #27795 from BerriAI/litellm_vcr-cache-observability-and-fixes-c5bc 2026-05-14 13:51:16 -07:00
scim_tests
search_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
spend_tracking_tests chore(proxy): guard sensitive public endpoints 2026-04-30 11:52:47 -07:00
store_model_in_db_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_litellm fix(proxy): redact SHA-256 token hash from 429 error body (#27884) 2026-05-16 03:55:18 +08:00
unified_google_tests test(vcr): classify cache verdicts, detect live calls, surface cost leaks 2026-05-13 00:31:47 +00:00
vector_store_tests fix: drop milvus dbName and partitionNames from MILVUS_OPTIONAL_PARAMS 2026-04-30 11:51:32 -07:00
windows_tests style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
__init__.py
_flush_vcr_cache.py tests(vcr): isolate cassette redis to CASSETTE_REDIS_URL 2026-05-01 12:32:59 -07:00
_vcr_conftest_common.py fix(vcr): aggregate worker stats on the controller so the session summary actually renders under xdist 2026-05-13 07:24:32 +00:00
_vcr_redis_persister.py test: add 24hr Redis-backed VCR cache to additional test suites (#27159) 2026-05-05 15:13:31 -07:00
eval_swe_bench.py Prompt Compression - add it to the proxy (#25729) 2026-04-20 15:08:00 -07:00
gettysburg.wav
large_text.py
openai_batch_completions.jsonl
README.MD
test_budget_management.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_callbacks_on_proxy.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_config.py
test_debug_warning.py
test_default_encoding_non_root.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_end_users.py
test_entrypoint.py
test_fallbacks.py
test_gpt5_azure_temperature_support.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_health.py fix(tests): swap dall-e to gpt-image-1 after openai deprecation 2026-05-12 16:55:18 -07:00
test_keys.py fix(tests): swap dall-e to gpt-image-1 after openai deprecation 2026-05-12 16:55:18 -07:00
test_litellm_proxy_responses_config.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_logging.conf
test_models.py test: replace test_add_and_delete_models integration test with mock 2026-03-30 21:30:57 -07:00
test_new_vector_store_endpoints.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_openai_endpoints.py fix(tests): swap dall-e to gpt-image-1 after openai deprecation 2026-05-12 16:55:18 -07:00
test_organizations.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_otel_thread_leak.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_passthrough_endpoints.py
test_presidio_latency.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_proxy_server_non_root.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_ratelimit.py [Fix] test_ratelimit: skip over-limit cases that race with background RPM tracking 2026-04-11 13:08:59 -07:00
test_resource_cleanup.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_service_logger_otel.py
test_spend_logs.py
test_team.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_team_logging.py test: cleanup dead tests 2026-03-28 20:49:02 -07:00
test_team_members.py
test_users.py Fix: tag budget reset must drop stale management-cache entry (#27568) 2026-05-10 00:18:55 +00:00

In total litellm runs 1000+ tests

[02/20/2025] Update:

To make it easier to contribute and map what behavior is tested,

we've started mapping the litellm directory in tests/test_litellm

This folder can only run mock tests.