fix(ui): derive UI cookie path from the last /ui segment

getUiCookiePath matched the first /ui segment, but the UI mounts at the last
one (SERVER_ROOT_PATH + /ui). For a root path that itself contains a /ui
segment (e.g. SERVER_ROOT_PATH=/foo/ui/bar), it resolved the wrong path, so
logout cleared the wrong cookie paths and left the scoped auth cookie in
place. Use the last /ui match so both the stored login cookie and the logout
clearing target the correct server root path.
This commit is contained in:
Syed Ali Abbas Rahil 2026-07-07 20:57:47 +09:00
parent da46d7e237
commit 27668d00bd
3 changed files with 20 additions and 4 deletions

View file

@ -645,7 +645,6 @@ from litellm.proxy.utils import (
_is_valid_team_configs,
evict_config_param,
get_config_param,
get_cookie_path_from_server_root_path,
get_custom_url,
get_error_message_str,
get_server_root_path,

View file

@ -142,6 +142,20 @@ describe("cookieUtils", () => {
vi.restoreAllMocks();
});
it("should clear token cookie at the server root path when the root path contains a /ui segment", () => {
const originalLocation = window.location;
vi.stubGlobal("location", { ...originalLocation, pathname: "/foo/ui/bar/ui/" });
const cookieSpy = vi.spyOn(document, "cookie", "set");
clearTokenCookies();
expect(cookieSpy).toHaveBeenCalledWith(expect.stringContaining("path=/foo/ui/bar;"));
vi.unstubAllGlobals();
vi.restoreAllMocks();
});
it("should clear sessionStorage token", () => {
sessionStorage.setItem("token", "stored-token");
clearTokenCookies();

View file

@ -14,9 +14,12 @@ function getUiCookiePath(): string {
if (typeof window === "undefined") return "/ui";
// Match "/ui" only as a full path segment (followed by "/" or end of string)
// to avoid false matches like "/my-ui-tool/login" → "/my-ui".
const match = window.location.pathname.match(/\/ui(?=\/|$)/);
if (match && match.index !== undefined) {
return window.location.pathname.substring(0, match.index + 3);
// The UI mounts at the last "/ui" segment (SERVER_ROOT_PATH + "/ui"), so use the
// last match to stay correct when the root path itself contains a "/ui" segment.
const matches = [...window.location.pathname.matchAll(/\/ui(?=\/|$)/g)];
const lastMatch = matches[matches.length - 1];
if (lastMatch && lastMatch.index !== undefined) {
return window.location.pathname.substring(0, lastMatch.index + 3);
}
return "/ui";
}