fix(ui): clear auth token cookie at server root path on logout

The server-set token cookie is now scoped to SERVER_ROOT_PATH, so logout
must also clear it at that path. clearTokenCookies only cleared "/", the
UI path, and the current directory, leaving the server-root-scoped cookie
in place; a logged-out user's session could be restored on path-mounted
deployments. Derive the server root path from the UI cookie path and clear
the token cookie there as well.
This commit is contained in:
Syed Ali Abbas Rahil 2026-07-07 20:41:22 +09:00
parent b5edd4acfc
commit da46d7e237
2 changed files with 21 additions and 0 deletions

View file

@ -128,6 +128,20 @@ describe("cookieUtils", () => {
vi.restoreAllMocks();
});
it("should clear token cookie at the server root path when deployed under SERVER_ROOT_PATH", () => {
const originalLocation = window.location;
vi.stubGlobal("location", { ...originalLocation, pathname: "/litellm/ui/" });
const cookieSpy = vi.spyOn(document, "cookie", "set");
clearTokenCookies();
expect(cookieSpy).toHaveBeenCalledWith(expect.stringContaining("path=/litellm;"));
vi.unstubAllGlobals();
vi.restoreAllMocks();
});
it("should clear sessionStorage token", () => {
sessionStorage.setItem("token", "stored-token");
clearTokenCookies();

View file

@ -38,6 +38,13 @@ export function clearTokenCookies() {
const uiCookiePath = getUiCookiePath();
const paths = ["/", uiCookiePath];
// Clear at the server root path (e.g. "/litellm") too, since the server-set
// auth cookie is scoped there when SERVER_ROOT_PATH is configured.
const serverRootPath = uiCookiePath.replace(/\/ui$/, "");
if (serverRootPath && !paths.includes(serverRootPath)) {
paths.push(serverRootPath);
}
// Add the current path directory if it's different from root and /ui
if (currentPath && currentPath !== "/" && !currentPath.startsWith("/ui")) {
const dirPath = currentPath.substring(0, currentPath.lastIndexOf("/") + 1);