mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-29 01:42:19 +00:00
* fix: enforce disable_custom_api_keys from general_settings The gate in _check_custom_key_allowed read the persisted UI settings row through get_ui_settings_cached, which had two consequences. A config-file general_settings.disable_custom_api_keys was never enforced, because the gate only ever looked at the stored ui_settings row. POST /key/generate with a custom key value returned 200 even with the flag set to true in config.yaml. The read went through a DualCache with a 600s TTL, which is per worker without Redis, and only the worker that served PATCH /update/ui_settings refreshed it. A gate flipped through the UI was then a coin flip across workers for up to ten minutes. Both go away by routing the flag the way the other runtime UI flags are already routed. Adding it to _RUNTIME_GENERAL_SETTINGS_FLAGS and to the settings rules' _UI_SETTINGS_FIELDS makes SettingsStore resolve it from the ui_settings row with the config file winning, and every pod re-reads it on its own settings sync rather than holding a private cached copy. The two lists have to stay in step: a flag in one and not the other resolves against the wrong stored row and silently never reaches a reader, so there is a test for that invariant. Writes to the ui_settings table did not publish on the config-sync channel, so other pods only discovered a change on their next periodic reload. Adding litellm_uisettings to _CONFIG_SYNCED_TABLE_NAMES puts it on the same pubsub path model and SSO config writes already use, which cuts cross-pod propagation from tens of seconds to a few. The value reaching the gate is run through coerce_bool first. Resolution hands back the raw YAML value, so a quoted "true" in config.yaml is a str and the old `is True` check let custom keys straight through. * test: assert both directions of the coerced config value * test: assert the runtime flags read back instead of inspecting the registry |
||
|---|---|---|
| .. | ||
| html_forms | ||
| admin_ui_utils.py | ||
| auth_cache_invalidation_pubsub.py | ||
| banner.py | ||
| cache_coordinator.py | ||
| cache_pydantic_utils.py | ||
| callback_config_validation.py | ||
| callback_utils.py | ||
| config_includes.py | ||
| config_sync_pubsub.py | ||
| custom_openapi_spec.py | ||
| debug_utils.py | ||
| encrypt_decrypt_utils.py | ||
| error_body_call_id.py | ||
| expired_ui_session_key_cleanup_manager.py | ||
| get_routes.py | ||
| healthy_model_filter.py | ||
| http_parsing_utils.py | ||
| json_merge_patch.py | ||
| key_rotation_manager.py | ||
| load_config_utils.py | ||
| model_deprecation.py | ||
| model_listing_utils.py | ||
| openai_endpoint_utils.py | ||
| openai_error_payload.py | ||
| openapi_schema_compat.py | ||
| path_utils.py | ||
| periodic_reload_schedule.py | ||
| prompt_cache_pricing.py | ||
| proxy_rate_limit_error.py | ||
| proxy_state.py | ||
| rbac_utils.py | ||
| realtime_utils.py | ||
| registry_read_through.py | ||
| reset_budget_job.py | ||
| resource_ownership.py | ||
| responses_stream_errors.py | ||
| scheduled_job_stagger.py | ||
| semantic_text_index.py | ||
| sse_keepalive.py | ||
| static_asset_utils.py | ||
| swagger_utils.py | ||
| timezone_utils.py | ||
| user_api_key_cache.py | ||