fix(ui): clear session state synchronously before awaiting proxy settings on logout

Veria flagged that logout awaited the proxy settings request before
clearing the token cookie, so a stalled settings endpoint would leave the
session usable after the user clicked Logout. Cookies, the stored return
URL, and worker localStorage are now cleared synchronously on click; the
settings await only decides the redirect target and authenticates via the
captured accessToken, not the cookie.
This commit is contained in:
ryan-crabbe-berri 2026-07-24 18:13:05 -07:00
parent e8c8d9ba22
commit 917734b104
2 changed files with 8 additions and 1 deletions

View file

@ -13,11 +13,11 @@ export function useLogout(accessToken: string | null): () => Promise<void> {
useProxySettings(accessToken);
return async () => {
const settings = await ensureProxySettings(queryClient, accessToken).catch(() => null);
clearTokenCookies();
clearStoredReturnUrl();
localStorage.removeItem("litellm_selected_worker_id");
localStorage.removeItem("litellm_worker_url");
const settings = await ensureProxySettings(queryClient, accessToken).catch(() => null);
window.location.replace(settings?.PROXY_LOGOUT_URL || getLoginUrl(getProxyBaseUrl()));
};
}

View file

@ -344,6 +344,11 @@ describe("Navbar", () => {
const user = userEvent.setup();
vi.mocked(window.location.replace).mockClear();
const cookieUtils = vi.mocked(await import("@/utils/cookieUtils"));
const returnUrlUtils = vi.mocked(await import("@/utils/returnUrlUtils"));
cookieUtils.clearTokenCookies.mockClear();
returnUrlUtils.clearStoredReturnUrl.mockClear();
const proxyUtils = vi.mocked(await import("@/utils/proxyUtils"));
let resolveSettings!: (value: { PROXY_BASE_URL: string; PROXY_LOGOUT_URL: string }) => void;
proxyUtils.fetchProxySettings.mockImplementationOnce(
@ -364,6 +369,8 @@ describe("Navbar", () => {
await user.click(screen.getByText("Logout"));
expect(window.location.replace).not.toHaveBeenCalled();
expect(cookieUtils.clearTokenCookies).toHaveBeenCalled();
expect(returnUrlUtils.clearStoredReturnUrl).toHaveBeenCalled();
resolveSettings({ PROXY_BASE_URL: "", PROXY_LOGOUT_URL: "https://sso.example.com/logout" });