From 203f493596e3d0bd888563543a25f09bbc634882 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Tue, 28 Apr 2026 16:50:16 -0700 Subject: [PATCH] fix(proxy): block /ui/* static routes when DISABLE_ADMIN_UI=true --- litellm/proxy/proxy_server.py | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/proxy_server.py b/litellm/proxy/proxy_server.py index 3982d096e69..c5199530ff1 100644 --- a/litellm/proxy/proxy_server.py +++ b/litellm/proxy/proxy_server.py @@ -302,6 +302,7 @@ from litellm.proxy.common_utils.encrypt_decrypt_utils import ( decrypt_value_helper, encrypt_value_helper, ) +from litellm.proxy.common_utils.admin_ui_utils import admin_ui_disabled from litellm.proxy.common_utils.html_forms.ui_login import build_ui_login_form from litellm.proxy.common_utils.http_parsing_utils import ( _read_request_body, @@ -1454,7 +1455,19 @@ try: ) # print(f"mounted _next at {server_root_path}/ui/_next") - app.mount("/ui", StaticFiles(directory=ui_path, html=True), name="ui") + _disable_admin_ui = str_to_bool(os.getenv("DISABLE_ADMIN_UI", "false")) is True + if _disable_admin_ui: + + @app.get("/ui/{path:path}") + async def ui_disabled_path(path: str): + return admin_ui_disabled() + + @app.get("/ui") + async def ui_disabled_root(): + return admin_ui_disabled() + + else: + app.mount("/ui", StaticFiles(directory=ui_path, html=True), name="ui") def _restructure_ui_html_files(ui_root: str) -> None: """Ensure each exported HTML route is available as /index.html."""