mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-27 01:22:18 +00:00
* fix(mcp-oauth): add PROXY_BASE_URL escape hatch + diagnostic logging for invalid_request
Customers hitting "{"detail":"invalid_request"}" on the MCP /authorize
endpoint had no way to recover when their ingress mangles X-Forwarded-*
headers (the same-origin check in validate_trusted_redirect_uri compares
the browser-supplied redirect_uri against get_request_base_url, which is
reconstructed from those headers).
Two contained changes:
1. get_request_base_url now honours PROXY_BASE_URL as the canonical
public origin when set, bypassing the X-Forwarded-* trust gate
entirely. Operators who know their public URL can set it once
instead of debugging ingress header rewrites.
2. The rejection path in validate_trusted_redirect_uri emits a WARN
log carrying the redirect_uri, computed proxy base, and the
X-Forwarded-* / Host headers seen. A bare 400 was undiagnosable;
this turns it into a one-line root-cause.
* test(mcp-oauth): capture warnings from correct logger ("LiteLLM")
Co-authored-by: Yassin Kortam <yassin@berri.ai>
* fix(mcp-oauth): reject malformed PROXY_BASE_URL with one-shot diagnostic
A scheme-less PROXY_BASE_URL (e.g. "litellm.example.com" instead of
"https://litellm.example.com") would sail through urlparse with empty
scheme + netloc, silently breaking every same-origin compare in
validate_trusted_redirect_uri and leaving the operator staring at the
same opaque 400 the env var was meant to fix.
Validate it once at read time: only honour values that parse as
http(s) URLs with a non-empty netloc; otherwise log a one-shot WARN
naming the bad value and fall through to the request-derived origin
so the proxy still serves traffic.
* fix(mcp/oauth): normalize PROXY_BASE_URL to strip query/fragment
Match the X-Forwarded-* path's normalization so a configured
PROXY_BASE_URL containing a query string or fragment does not break
downstream f-string concatenation like f"{base_url}/callback".
Co-authored-by: Yassin Kortam <yassin@berri.ai>
* refactor(mcp-oauth): drop non-essential comments from PROXY_BASE_URL changes
Strip narrative comments and verbose docstrings added in this PR; the
code is intuitive enough on its own and the log messages already carry
their own diagnostic context. Pre-existing comments are left untouched.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Yassin Kortam <yassin@berri.ai>
|
||
|---|---|---|
| .. | ||
| _experimental | ||
| agent_endpoints | ||
| analytics_endpoints | ||
| anthropic_endpoints | ||
| auth | ||
| batches_endpoints | ||
| client | ||
| common_utils | ||
| config_management_endpoints | ||
| container_endpoints | ||
| credential_endpoints | ||
| custom_hooks | ||
| db | ||
| discovery_endpoints | ||
| example_config_yaml | ||
| fine_tuning_endpoints | ||
| google_endpoints | ||
| guardrails | ||
| health_check_utils | ||
| health_endpoints | ||
| hooks | ||
| image_endpoints | ||
| management_endpoints | ||
| management_helpers | ||
| memory | ||
| middleware | ||
| ocr_endpoints | ||
| openai_evals_endpoints | ||
| openai_files_endpoints | ||
| pass_through_endpoints | ||
| policy_engine | ||
| prompts | ||
| public_endpoints | ||
| rag_endpoints | ||
| realtime_endpoints | ||
| rerank_endpoints | ||
| response_api_endpoints | ||
| response_polling | ||
| search_endpoints | ||
| spend_tracking | ||
| swagger | ||
| test_prompts | ||
| types_utils | ||
| ui_crud_endpoints | ||
| vector_store_endpoints | ||
| vector_store_files_endpoints | ||
| vertex_ai_endpoints | ||
| video_endpoints | ||
| workflows | ||
| .gitignore | ||
| __init__.py | ||
| _lazy_features.py | ||
| _lazy_openapi_snapshot.json | ||
| _lazy_openapi_snapshot.py | ||
| _logging.py | ||
| _new_new_secret_config.yaml | ||
| _new_secret_config.yaml | ||
| _super_secret_config.yaml | ||
| _types.py | ||
| cached_logo.jpg | ||
| caching_routes.py | ||
| common_request_processing.py | ||
| compliance_checks.py | ||
| custom_auth_auto.py | ||
| custom_prompt_management.py | ||
| custom_sso.py | ||
| custom_validate.py | ||
| dd_span_tagger.py | ||
| enterprise | ||
| health_check.py | ||
| lambda.py | ||
| litellm_pre_call_utils.py | ||
| llamaguard_prompt.txt | ||
| logo.jpg | ||
| mcp_registry.json | ||
| mcp_tools.py | ||
| model_config.yaml | ||
| openapi.json | ||
| openapi_registry.json | ||
| post_call_rules.py | ||
| prisma_migration.py | ||
| prometheus_cleanup.py | ||
| proxy_cli.py | ||
| proxy_config.yaml | ||
| proxy_server.py | ||
| README.md | ||
| route_llm_request.py | ||
| schema.prisma | ||
| start.sh | ||
| utils.py | ||
litellm-proxy
A local, fast, and lightweight OpenAI-compatible server to call 100+ LLM APIs.
usage
$ uv tool install litellm
$ litellm --model ollama/codellama
#INFO: Ollama running on http://0.0.0.0:8000
replace openai base
import openai # openai v1.0.0+
client = openai.OpenAI(api_key="anything",base_url="http://0.0.0.0:8000") # set proxy to base_url
# request sent to model set on litellm proxy, `litellm --model`
response = client.chat.completions.create(model="gpt-3.5-turbo", messages = [
{
"role": "user",
"content": "this is a test request, write a short poem"
}
])
print(response)
See how to call Huggingface,Bedrock,TogetherAI,Anthropic, etc.
Folder Structure
Routes
proxy_server.py- all openai-compatible routes -/v1/chat/completion,/v1/embedding+ model info routes -/v1/models,/v1/model/info,/v1/model_group_inforoutes.health_endpoints/-/health,/health/liveliness,/health/readinessmanagement_endpoints/key_management_endpoints.py- all/key/*routesmanagement_endpoints/team_endpoints.py- all/team/*routesmanagement_endpoints/internal_user_endpoints.py- all/user/*routesmanagement_endpoints/ui_sso.py- all/sso/*routes