mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-06 02:48:13 +00:00
fix(security): remove accessToken from sessionStorage in OAuth flow state
The LiteLLM API key was being serialised into sessionStorage as part of StoredFlowState. After the OAuth redirect the component re-mounts with the same accessToken prop, so it never needed to be stored. Read it from props in resumeOAuthFlow instead.
This commit is contained in:
parent
170d6a3e56
commit
035c593999
1 changed files with 3 additions and 4 deletions
|
|
@ -54,7 +54,6 @@ type StoredFlowState = {
|
|||
redirectUri: string;
|
||||
clientId?: string;
|
||||
clientSecret?: string;
|
||||
accessToken: string;
|
||||
scopes?: string[];
|
||||
};
|
||||
|
||||
|
|
@ -175,7 +174,6 @@ export const useUserMcpOAuthFlow = ({
|
|||
redirectUri,
|
||||
clientId,
|
||||
clientSecret,
|
||||
accessToken,
|
||||
scopes,
|
||||
};
|
||||
|
||||
|
|
@ -240,7 +238,8 @@ export const useUserMcpOAuthFlow = ({
|
|||
});
|
||||
|
||||
// Persist the token for this user via the backend.
|
||||
await storeMCPOAuthUserCredential(flowState.accessToken, flowState.serverId, {
|
||||
// accessToken comes from props — it is never stored in sessionStorage.
|
||||
await storeMCPOAuthUserCredential(accessToken, flowState.serverId, {
|
||||
access_token: token.access_token,
|
||||
refresh_token: token.refresh_token,
|
||||
expires_in: token.expires_in,
|
||||
|
|
@ -260,7 +259,7 @@ export const useUserMcpOAuthFlow = ({
|
|||
clearStorage(FLOW_STATE_KEY);
|
||||
setTimeout(() => { processingRef.current = false; }, 1000);
|
||||
}
|
||||
}, [onSuccess]);
|
||||
}, [accessToken, onSuccess]);
|
||||
|
||||
useEffect(() => {
|
||||
resumeOAuthFlow();
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue