litellm/tests/test_litellm/proxy/spend_tracking
devin-ai-integration[bot] b487a80f4c
Some checks are pending
GitHub Actions Security Analysis / zizmor (push) Waiting to run
fix(security): hash Bearer-prefixed API keys in spend logs (#31799)
* fix(security): hash Bearer-prefixed API keys in spend logs

The safety-net hash in get_logging_payload only checked for keys
starting with 'sk-', missing keys that arrived as 'Bearer sk-...'.
This caused plaintext API keys to be stored in SpendLogs for failed
requests while successful requests correctly stored SHA256 hashes.

Adds _hash_api_key_for_spend_log that strips the Bearer prefix
before hashing, applied to both the api_key column and the
metadata.user_api_key field in spend log payloads.

* fix: strip Bearer prefix from non-sk keys in spend log fallback path

---------

Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-07-06 13:30:38 -07:00
..
test_budget_reservation_redis_failure.py fix(register_model): preserve built-in cache pricing when registering custom overrides under unmapped keys (#30044) 2026-06-10 12:11:03 -07:00
test_cloudzero_endpoints.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_spend_log_error_logger.py feat(spend-logs): opt-in suppression of stack traces in spend-tracking error logs 2026-05-02 00:44:34 +00:00
test_spend_management_endpoints.py fix(mcp): roll up MCP tool spend to user counters and usage UI (#31576) 2026-07-02 08:16:39 -07:00
test_spend_query_optimization.py fix(spend): filter /global/spend/report by team_id when group_by=team 2026-07-04 19:52:01 -07:00
test_spend_tracking_utils.py fix(security): hash Bearer-prefixed API keys in spend logs (#31799) 2026-07-06 13:30:38 -07:00