mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-04 02:31:27 +00:00
maybe_build_debug_headers used to promote client_ip=None to INTERNAL_REQUEST before resolving the server name, on the theory that debug-header generation is passive observability and shouldn't drop metadata when IP extraction failed. But when x-litellm-mcp-debug:true is sent on a request whose IP can't be attributed, that bypass leaks x-mcp-debug-outbound-url / x-mcp-debug-server-auth-type for any internal-only server named in the request — even though the IP gate would otherwise hide it. Pass client_ip straight through. The gate now fails closed for internal-only servers when IP extraction fails; the debug response falls back to "(unknown)" / "(none)" instead of leaking real upstream metadata. Internal callers (admin debug paths) still resolve normally because their request handlers supply a real internal IP. Add regression tests for both the leak-prevention path and the internal-IP resolution path. |
||
|---|---|---|
| .. | ||
| auth | ||
| guardrail_translation | ||
| test_byok_oauth_endpoints.py | ||
| test_db_credentials.py | ||
| test_discoverable_endpoints.py | ||
| test_is_tool_name_prefixed.py | ||
| test_jwt_mcp_enforcement.py | ||
| test_jwt_mcp_simple.py | ||
| test_mcp_cost_calculator.py | ||
| test_mcp_custom_fields.py | ||
| test_mcp_debug.py | ||
| test_mcp_discovery.py | ||
| test_mcp_hook_extra_headers.py | ||
| test_mcp_metadata_preservation.py | ||
| test_mcp_server.py | ||
| test_mcp_server_manager.py | ||
| test_mcp_sigv4_auth.py | ||
| test_mcp_stale_session.py | ||
| test_mcp_toolset_scope.py | ||
| test_oauth2_token_cache.py | ||
| test_openapi_to_mcp_generator.py | ||
| test_openapi_tool_auth.py | ||
| test_rest_endpoints.py | ||
| test_semantic_tool_filter.py | ||
| test_short_mcp_tool_prefix.py | ||
| test_ui_session_utils.py | ||