litellm/backend
yucheng e8cee19bee feat(proxy): default at-rest encryption to AES-256-GCM with HKDF v3 and make PyNaCl optional
New writes use v3:gcm: (AES-256-GCM under HKDF-SHA256). v2:gcm: and unprefixed
XSalsa20 values stay readable under the raw SHA-256 derivation they were written
with. xsalsa20-poly1305 remains an explicit opt-in and is refused under
LITELLM_FIPS_MODE. PyNaCl imports are lazy and a missing PyNaCl on legacy
ciphertext raises one error naming the legacy-encryption extra and the
re-encrypt path. pynacl moves from the proxy extra to legacy-encryption, which
the standard Dockerfiles install

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-24 08:32:05 +00:00
..
routes fix(proxy): revoke UI session tokens on logout and password change (#42463) 2026-09-23 10:31:38 +02:00
Dockerfile feat(proxy): default at-rest encryption to AES-256-GCM with HKDF v3 and make PyNaCl optional 2026-09-24 08:32:05 +00:00
main.py chore(oss): litellm oss staging 120626 (#30292) 2026-06-12 09:49:25 -07:00