mirror of
https://github.com/tiennm99/litellm.git
synced 2026-08-09 12:24:21 +00:00
Validate UI settings PATCH body against effective class
GET /get/ui_settings returns a schema built from the effective UISettings class (base + enterprise-registered fields), but PATCH /update/ui_settings declared its body as the base UISettings. Enterprise fields still worked via extra="allow", but the OpenAPI schema was asymmetric between GET and PATCH. Accept the body as a dict and validate with the effective class so both sides are in sync and enterprise-registered fields are type-checked.
This commit is contained in:
@@ -3,8 +3,8 @@ import json
|
||||
from typing import Any, Dict, List, Optional, Set, Tuple, Union
|
||||
from urllib.parse import urlparse
|
||||
|
||||
from fastapi import APIRouter, Depends, File, HTTPException, UploadFile
|
||||
from pydantic import ConfigDict, create_model
|
||||
from fastapi import APIRouter, Body, Depends, File, HTTPException, UploadFile
|
||||
from pydantic import ConfigDict, ValidationError, create_model
|
||||
from pydantic.fields import FieldInfo
|
||||
|
||||
import litellm
|
||||
@@ -1218,7 +1218,8 @@ async def get_ui_settings():
|
||||
dependencies=[Depends(user_api_key_auth)],
|
||||
)
|
||||
async def update_ui_settings(
|
||||
settings: UISettings, user_api_key_dict: UserAPIKeyAuth = Depends(user_api_key_auth)
|
||||
settings_body: Dict[str, Any] = Body(...),
|
||||
user_api_key_dict: UserAPIKeyAuth = Depends(user_api_key_auth),
|
||||
):
|
||||
"""
|
||||
Update UI-specific configuration flags.
|
||||
@@ -1245,6 +1246,14 @@ async def update_ui_settings(
|
||||
},
|
||||
)
|
||||
|
||||
# Validate against the same effective class GET advertises, so
|
||||
# enterprise-registered fields are typed consistently on both sides.
|
||||
effective_cls = _get_effective_ui_settings_class()
|
||||
try:
|
||||
settings = effective_cls.model_validate(settings_body)
|
||||
except ValidationError as e:
|
||||
raise HTTPException(status_code=422, detail=e.errors())
|
||||
|
||||
# Only include fields the caller actually sent (not Pydantic defaults).
|
||||
settings_dict = settings.model_dump(exclude_unset=True)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user