mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-10 03:28:53 +00:00
fix(ui): scope deleteCookie sessionStorage cleanup to token key only
Also document the sessionStorage cross-tab trade-off: per-tab scope means users behind an HttpOnly proxy must log in once per tab, but this is intentional to avoid localStorage XSS exposure. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
523d1c388f
commit
acdc6145b3
2 changed files with 10 additions and 4 deletions
|
|
@ -56,10 +56,12 @@ import { ConfigProvider, theme } from "antd";
|
|||
function deleteCookie(name: string, path = "/") {
|
||||
// Best-effort client-side clear (works for non-HttpOnly cookies without Domain)
|
||||
document.cookie = `${name}=; Max-Age=0; Path=${path}`;
|
||||
try {
|
||||
sessionStorage.removeItem(name);
|
||||
} catch {
|
||||
// sessionStorage may be unavailable
|
||||
if (name === "token") {
|
||||
try {
|
||||
sessionStorage.removeItem(name);
|
||||
} catch {
|
||||
// sessionStorage may be unavailable
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -56,6 +56,10 @@ export function clearTokenCookies() {
|
|||
* Stores the login token in sessionStorage.
|
||||
* This ensures the token is available even when a reverse proxy adds HttpOnly
|
||||
* to server-set cookies, making them invisible to JavaScript.
|
||||
*
|
||||
* Note: sessionStorage is per-tab, so users behind an HttpOnly proxy must log
|
||||
* in once per tab. We intentionally avoid localStorage here because it persists
|
||||
* after browser close and is readable by any injected script (XSS).
|
||||
*/
|
||||
export function storeLoginToken(token: string) {
|
||||
if (typeof window === "undefined") return;
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue