From da46d7e237356d08c67e84f8d2aebc352d9cfb41 Mon Sep 17 00:00:00 2001 From: Syed Ali Abbas Rahil Date: Tue, 7 Jul 2026 20:41:22 +0900 Subject: [PATCH] fix(ui): clear auth token cookie at server root path on logout The server-set token cookie is now scoped to SERVER_ROOT_PATH, so logout must also clear it at that path. clearTokenCookies only cleared "/", the UI path, and the current directory, leaving the server-root-scoped cookie in place; a logged-out user's session could be restored on path-mounted deployments. Derive the server root path from the UI cookie path and clear the token cookie there as well. --- ui/litellm-dashboard/src/utils/cookieUtils.test.ts | 14 ++++++++++++++ ui/litellm-dashboard/src/utils/cookieUtils.ts | 7 +++++++ 2 files changed, 21 insertions(+) diff --git a/ui/litellm-dashboard/src/utils/cookieUtils.test.ts b/ui/litellm-dashboard/src/utils/cookieUtils.test.ts index a38b96e74c2..a6f39b96996 100644 --- a/ui/litellm-dashboard/src/utils/cookieUtils.test.ts +++ b/ui/litellm-dashboard/src/utils/cookieUtils.test.ts @@ -128,6 +128,20 @@ describe("cookieUtils", () => { vi.restoreAllMocks(); }); + it("should clear token cookie at the server root path when deployed under SERVER_ROOT_PATH", () => { + const originalLocation = window.location; + vi.stubGlobal("location", { ...originalLocation, pathname: "/litellm/ui/" }); + + const cookieSpy = vi.spyOn(document, "cookie", "set"); + + clearTokenCookies(); + + expect(cookieSpy).toHaveBeenCalledWith(expect.stringContaining("path=/litellm;")); + + vi.unstubAllGlobals(); + vi.restoreAllMocks(); + }); + it("should clear sessionStorage token", () => { sessionStorage.setItem("token", "stored-token"); clearTokenCookies(); diff --git a/ui/litellm-dashboard/src/utils/cookieUtils.ts b/ui/litellm-dashboard/src/utils/cookieUtils.ts index 66eb807ed2d..d4b2c6a2490 100644 --- a/ui/litellm-dashboard/src/utils/cookieUtils.ts +++ b/ui/litellm-dashboard/src/utils/cookieUtils.ts @@ -38,6 +38,13 @@ export function clearTokenCookies() { const uiCookiePath = getUiCookiePath(); const paths = ["/", uiCookiePath]; + // Clear at the server root path (e.g. "/litellm") too, since the server-set + // auth cookie is scoped there when SERVER_ROOT_PATH is configured. + const serverRootPath = uiCookiePath.replace(/\/ui$/, ""); + if (serverRootPath && !paths.includes(serverRootPath)) { + paths.push(serverRootPath); + } + // Add the current path directory if it's different from root and /ui if (currentPath && currentPath !== "/" && !currentPath.startsWith("/ui")) { const dirPath = currentPath.substring(0, currentPath.lastIndexOf("/") + 1);