mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
_attach_keys_to_agents joins keys onto the agent response by agent_id with no caller scoping, but _redact_sensitive_agent_fields never cleared the new keys field. A non-admin able to view an agent therefore received the alias, masked name, and hashed token of every key attached to it, including keys owned by other users or teams; the old client-side path used the scoped key list, so this was a visibility regression. Clear keys in the redaction path so only admins see attached-key metadata. Adds an endpoint-level regression test asserting keys is populated for admins and null for non-admins, and a list-view test covering the Active vs Needs Setup badge that lost coverage when the agent card tests were removed. |
||
|---|---|---|
| .. | ||
| litellm-dashboard | ||
| Dockerfile | ||
| nginx.conf | ||