litellm/tests/test_litellm/proxy/_experimental
mateo-berri ec3c67084f
security(mcp): strip Authorization in call_tool when LiteLLM admission used legacy header
Mirror the OAuth pass-through admission check from _prepare_mcp_server_headers
(list-tools path) in _call_regular_mcp_tool (tool-call path): when the server
is OAuth pass-through and the caller did not supply x-litellm-api-key,
Authorization on the inbound request may itself be the LiteLLM API key — so
strip it before forwarding instead of leaking the gateway credential upstream.

When x-litellm-api-key is present, admission is unambiguous and Authorization
continues to carry the upstream OAuth bearer (transparent pass-through).
2026-05-21 17:56:49 +00:00
..
mcp_server security(mcp): strip Authorization in call_tool when LiteLLM admission used legacy header 2026-05-21 17:56:49 +00:00