fix: address Greptile review feedback

- Add window guard to setTokenCookie for SSR consistency with clearTokenCookies
- Add SSR test for window undefined case
- Add code comment explaining why JWT is included in response body

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Hendrik Jaks 2026-03-13 10:02:10 +02:00
parent 6eb78e46c9
commit a8864ea12b
3 changed files with 16 additions and 1 deletions

View file

@ -11029,6 +11029,9 @@ async def login_v2(request: Request): # noqa: PLR0915
litellm_dashboard_ui += "/ui/"
litellm_dashboard_ui += "?login=success"
# Token is included in the response body so the UI can set a JS-accessible
# cookie even when a reverse proxy (e.g. nginx-ingress) adds HttpOnly to the
# server-set cookie, which would otherwise cause an infinite login redirect.
json_response = JSONResponse(
content={"redirect_url": litellm_dashboard_ui, "token": jwt_token},
status_code=status.HTTP_200_OK,

View file

@ -140,6 +140,18 @@ describe("cookieUtils", () => {
global.document = originalDocument;
});
it("should not throw when window is undefined (server-side rendering)", () => {
const originalWindow = global.window;
const originalDocument = global.document;
delete (global as any).window;
delete (global as any).document;
expect(() => setTokenCookie("token")).not.toThrow();
global.window = originalWindow;
global.document = originalDocument;
});
});
describe("getCookie", () => {

View file

@ -51,7 +51,7 @@ export function clearTokenCookies() {
* This ensures the token is JS-accessible even when a reverse proxy adds HttpOnly to server-set cookies.
*/
export function setTokenCookie(token: string) {
if (typeof document === "undefined") return;
if (typeof window === "undefined" || typeof document === "undefined") return;
const isSecure = window.location.protocol === "https:";
document.cookie = `token=${token}; Path=/; SameSite=Lax${isSecure ? "; Secure" : ""}`;
}