mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-23 00:41:40 +00:00
The OAuth proxy endpoints /authorize, /token, and /register sit mid-OAuth- handshake and can't require Depends(user_api_key_auth). They forward to admin-configured token_url and registration_url. An unauthenticated caller hitting /token or /register made the proxy POST to whatever URL the admin configured for the MCP server, which let an internal IdP be probed via the proxy if the admin had registered one. Validate the outbound URL through litellm_core_utils.url_utils.validate_url before each POST in register_client_with_server and exchange_token_with_server. The helper resolves DNS, blocks RFC1918 / loopback / link-local destinations, honours the existing user_url_allowed_hosts allowlist, and rewrites the URL to the validated IP to defeat DNS rebinding. Operators who need to point at an internal IdP can opt in via the same allowlist that other outbound URL-validation sites use, or set litellm.user_url_validation = False. Separately, _is_server_accessible_from_ip used to fail open when client_ip was None, which let request handlers that couldn't determine a client IP reach internal-only servers. Lock the contract: None now fails closed and internal callers must pass the new INTERNAL_REQUEST sentinel to bypass IP gating. get_mcp_server_by_name keeps its existing "None means internal" wrapper convention by translating to the sentinel internally, so internal callers (auth, debug, registry maintenance) continue to work unchanged. The user-facing callsites in rest_endpoints that previously short-circuited on client_ip is None now hit the gate and inherit the fail-closed behaviour. |
||
|---|---|---|
| .. | ||
| agent_tests | ||
| audio_tests | ||
| basic_proxy_startup_tests | ||
| batches_tests | ||
| benchmarks | ||
| code_coverage_tests | ||
| documentation_tests | ||
| enterprise | ||
| guardrails_tests | ||
| image_gen_tests | ||
| litellm | ||
| litellm-proxy-extras | ||
| litellm_core_utils | ||
| litellm_utils_tests | ||
| llm_responses_api_testing | ||
| llm_translation | ||
| load_tests | ||
| local_testing | ||
| logging_callback_tests | ||
| mcp_tests | ||
| multi_instance_e2e_tests | ||
| ocr_tests | ||
| old_proxy_tests/tests | ||
| openai_endpoints_tests | ||
| otel_tests | ||
| pass_through_tests | ||
| pass_through_unit_tests | ||
| proxy_admin_ui_tests | ||
| proxy_e2e_anthropic_messages_tests | ||
| proxy_security_tests | ||
| proxy_unit_tests | ||
| router_unit_tests | ||
| scim_tests | ||
| search_tests | ||
| spend_tracking_tests | ||
| store_model_in_db_tests | ||
| test_litellm | ||
| unified_google_tests | ||
| vector_store_tests | ||
| windows_tests | ||
| __init__.py | ||
| _flush_vcr_cache.py | ||
| _vcr_conftest_common.py | ||
| _vcr_redis_persister.py | ||
| eval_swe_bench.py | ||
| gettysburg.wav | ||
| large_text.py | ||
| openai_batch_completions.jsonl | ||
| README.MD | ||
| test_budget_management.py | ||
| test_callbacks_on_proxy.py | ||
| test_config.py | ||
| test_debug_warning.py | ||
| test_default_encoding_non_root.py | ||
| test_end_users.py | ||
| test_entrypoint.py | ||
| test_fallbacks.py | ||
| test_gpt5_azure_temperature_support.py | ||
| test_health.py | ||
| test_keys.py | ||
| test_litellm_proxy_responses_config.py | ||
| test_logging.conf | ||
| test_models.py | ||
| test_new_vector_store_endpoints.py | ||
| test_openai_endpoints.py | ||
| test_organizations.py | ||
| test_otel_thread_leak.py | ||
| test_passthrough_endpoints.py | ||
| test_presidio_latency.py | ||
| test_proxy_server_non_root.py | ||
| test_ratelimit.py | ||
| test_resource_cleanup.py | ||
| test_service_logger_otel.py | ||
| test_spend_logs.py | ||
| test_team.py | ||
| test_team_logging.py | ||
| test_team_members.py | ||
| test_users.py | ||
In total litellm runs 1000+ tests
[02/20/2025] Update:
To make it easier to contribute and map what behavior is tested,
we've started mapping the litellm directory in tests/test_litellm
This folder can only run mock tests.