mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-16 23:41:43 +00:00
Follow-up to merged #26859 (team-callback audit log). The variant scan from that PR flagged two more high-risk admin endpoints whose mutations weren't audit-logged: - ``POST /cache/settings`` (cache_settings_endpoints.py) — writes the team / global Redis cache configuration, including credentials. An admin (or compromised admin) flipping the cache backend is a data-routing pivot — every subsequent LLM response cache write goes to the new destination — so the action needs to be traceable. - ``POST /config_overrides/hashicorp_vault`` and ``DELETE /config_overrides/hashicorp_vault`` (config_override_endpoints.py) — control the proxy's KMS config. Mutating these affects every secret retrieval going forward. Each endpoint now emits an ``LiteLLM_AuditLogs`` row gated on ``litellm.store_audit_logs`` (Enterprise feature), mirroring the shape merged in #26859. Both helpers redact every field value before serialization (replacing them with ``***REDACTED***`` while keeping field names) so the audit table cannot itself become a credential-harvest sink — Redis passwords / vault tokens / ``approle_secret_id`` / ``client_key`` would otherwise be persisted in plaintext JSON. Both helpers also attach a ``done_callback`` that surfaces a ``verbose_proxy_logger.warning`` when the fire-and-forget audit-log task fails, so a transient DB error doesn't silently lose the row. Adds ``CACHE_CONFIG_TABLE_NAME`` / ``CONFIG_OVERRIDES_TABLE_NAME`` to ``LitellmTableNames`` so the audit rows co-locate with the table they mutate. Tests: - /cache/settings: emits when ``store_audit_logs=True``, no emission when off, plaintext credentials don't appear in the serialized row. - /config_overrides/hashicorp_vault POST: same, plus checks the redaction of ``vault_token`` and ``vault_addr``. - /config_overrides/hashicorp_vault DELETE: emits with ``action="deleted"`` only when an actual row was removed; idempotent delete of a non-existent row produces no audit log. |
||
|---|---|---|
| .. | ||
| agent_tests | ||
| audio_tests | ||
| basic_proxy_startup_tests | ||
| batches_tests | ||
| benchmarks | ||
| code_coverage_tests | ||
| documentation_tests | ||
| enterprise | ||
| guardrails_tests | ||
| image_gen_tests | ||
| litellm | ||
| litellm-proxy-extras | ||
| litellm_core_utils | ||
| litellm_utils_tests | ||
| llm_responses_api_testing | ||
| llm_translation | ||
| load_tests | ||
| local_testing | ||
| logging_callback_tests | ||
| mcp_tests | ||
| multi_instance_e2e_tests | ||
| ocr_tests | ||
| old_proxy_tests/tests | ||
| openai_endpoints_tests | ||
| otel_tests | ||
| pass_through_tests | ||
| pass_through_unit_tests | ||
| proxy_admin_ui_tests | ||
| proxy_e2e_anthropic_messages_tests | ||
| proxy_security_tests | ||
| proxy_unit_tests | ||
| router_unit_tests | ||
| scim_tests | ||
| search_tests | ||
| spend_tracking_tests | ||
| store_model_in_db_tests | ||
| test_litellm | ||
| unified_google_tests | ||
| vector_store_tests | ||
| windows_tests | ||
| __init__.py | ||
| eval_swe_bench.py | ||
| gettysburg.wav | ||
| large_text.py | ||
| openai_batch_completions.jsonl | ||
| README.MD | ||
| test_budget_management.py | ||
| test_callbacks_on_proxy.py | ||
| test_config.py | ||
| test_debug_warning.py | ||
| test_default_encoding_non_root.py | ||
| test_end_users.py | ||
| test_entrypoint.py | ||
| test_fallbacks.py | ||
| test_gpt5_azure_temperature_support.py | ||
| test_health.py | ||
| test_keys.py | ||
| test_litellm_proxy_responses_config.py | ||
| test_logging.conf | ||
| test_models.py | ||
| test_new_vector_store_endpoints.py | ||
| test_openai_endpoints.py | ||
| test_organizations.py | ||
| test_otel_thread_leak.py | ||
| test_passthrough_endpoints.py | ||
| test_presidio_latency.py | ||
| test_proxy_server_non_root.py | ||
| test_ratelimit.py | ||
| test_resource_cleanup.py | ||
| test_service_logger_otel.py | ||
| test_spend_logs.py | ||
| test_team.py | ||
| test_team_logging.py | ||
| test_team_members.py | ||
| test_users.py | ||
In total litellm runs 1000+ tests
[02/20/2025] Update:
To make it easier to contribute and map what behavior is tested,
we've started mapping the litellm directory in tests/test_litellm
This folder can only run mock tests.