Commit graph

39672 commits

Author SHA1 Message Date
吹雪
8708a1e614 feat(ui): i18n for mcp_tools batch 3 2026-06-10 19:05:15 +09:00
吹雪
c233d094cf fix(ui): collapse toolsetColumns params into options object to satisfy max-params 2026-06-10 18:55:52 +09:00
吹雪
dff009460e feat(ui): i18n for mcp_tools batch 2 2026-06-10 18:55:20 +09:00
吹雪
c3617bc3d2 feat(ui): i18n for mcp_tools batch 1 2026-06-10 18:45:29 +09:00
吹雪
dc9c44f3b1 feat(ui): i18n for guardrail params, table, LLM judge, and PII components 2026-06-10 18:31:29 +09:00
吹雪
eccf54a990 feat(ui): i18n for guardrail garden and info views 2026-06-10 18:19:57 +09:00
吹雪
327f3ad020 feat(ui): i18n for guardrails modals and edit form 2026-06-10 18:10:14 +09:00
吹雪
535e00626d feat(ui): i18n for guardrails content filter components 2026-06-10 17:58:30 +09:00
吹雪
59880539d3 chore(ui): prune stale eslint suppressions after i18n refactors 2026-06-10 17:48:45 +09:00
吹雪
faed97b869 feat(ui): i18n for add guardrail form 2026-06-10 17:48:14 +09:00
吹雪
6484d548ec feat(ui): i18n for team guardrails tab 2026-06-10 17:38:38 +09:00
吹雪
fbb8477d23 feat(ui): i18n for guardrail test playground 2026-06-10 17:31:31 +09:00
吹雪
95af75657c feat(ui): i18n for view_logs constants and filter options 2026-06-10 17:24:46 +09:00
吹雪
6bb974f1e8 feat(ui): i18n for view_logs batch 4 2026-06-10 17:18:52 +09:00
吹雪
888cc88826 feat(ui): i18n for view_logs batch 3 2026-06-10 14:57:20 +09:00
吹雪
1a1144fe76 feat(ui): i18n for view_logs batch 2 2026-06-10 14:48:15 +09:00
吹雪
e6704034de feat(ui): i18n for view_logs batch 1 2026-06-10 14:38:43 +09:00
吹雪
e93492321a feat(ui): i18n for user dashboard, user edit, and user spend views 2026-06-10 14:28:55 +09:00
吹雪
33ac749174 feat(ui): i18n for usage and user agent activity views 2026-06-10 14:22:47 +09:00
吹雪
30a4169b08 feat(ui): i18n for settings, route preview, transform request, and skill hub columns 2026-06-10 14:15:51 +09:00
吹雪
3fd97f0fcc feat(ui): i18n for public model hub 2026-06-10 14:04:18 +09:00
吹雪
b03c393a54 feat(ui): i18n for pass-through settings, per-user usage, price reload, and prompts 2026-06-10 13:51:24 +09:00
吹雪
38f2137eca feat(ui): i18n for organizations, pass-through info, and onboarding link 2026-06-10 13:43:39 +09:00
吹雪
7c0faa8bc6 feat(ui): i18n for model info view 2026-06-10 13:35:09 +09:00
吹雪
4018f9a836 feat(ui): i18n for model filters, group alias settings, and hub columns 2026-06-10 13:24:49 +09:00
吹雪
625feb0ab7 feat(ui): i18n for top-level components batch 8 2026-06-10 13:19:22 +09:00
吹雪
eb53553d24 feat(ui): i18n for bulk user creation and cache views 2026-06-10 13:07:59 +09:00
吹雪
b2abda084f feat(ui): i18n for activity metrics, pass-through endpoints, and agents panel 2026-06-10 13:00:51 +09:00
吹雪
1746865a7b feat(ui): i18n for tool policies, UI access control, and usage indicator 2026-06-10 12:53:03 +09:00
吹雪
2980302d96 feat(ui): i18n for SCIM, SSO modals, team SSO settings, and tool detail 2026-06-10 12:43:20 +09:00
吹雪
7bf4de9997 feat(ui): i18n for legacy teams view 2026-06-10 12:35:26 +09:00
吹雪
cb21813d80 feat(ui): i18n for help link component 2026-06-10 12:25:12 +09:00
吹雪
867abf24f9 feat(ui): i18n for top-level components batch 1 2026-06-10 12:21:22 +09:00
吹雪
bd289dc5e8 feat(ui): i18n for navbar notifications bell and user dropdown leftovers 2026-06-10 12:06:49 +09:00
吹雪
60f73e1eb6 feat(ui): i18n for user search modal 2026-06-10 12:02:45 +09:00
吹雪
c084e10de9 feat(ui): i18n for common_components batch 2 2026-06-10 11:59:23 +09:00
吹雪
77fbc36e94 feat(ui): i18n for common_components batch 1 2026-06-10 11:52:00 +09:00
吹雪
019dfcbe23 feat(ui): i18n for molecules filter, model columns, and notifications manager 2026-06-10 11:43:41 +09:00
吹雪
a851b90d4b feat(ui): i18n for shared date pickers and created key display 2026-06-10 11:33:01 +09:00
吹雪
f737f979d7 feat(ui): seed common i18n namespace with shared action and status terms 2026-06-10 11:22:47 +09:00
吹雪
7436e4ce0b Merge remote-tracking branch 'origin/litellm_internal_staging' into litellm_ui_i18n 2026-06-10 10:55:03 +09:00
ryan-crabbe-berri
9e0d92c129
chore(ui): remove dead dashboard files and unused dependencies (#30047)
* chore(ui): remove dead dashboard files and unused dependencies

knip flagged seven orphaned source/config files with no importers and
five declared dependencies that nothing in the tree uses. Removing them
shrinks the dashboard bundle's source surface and keeps the manifest
honest; vite stays installed transitively via vitest, so test tooling is
unaffected.

* fix(ci): restore serverRootPath.config.ts referenced by SERVER_ROOT_PATH workflow

The dead-code sweep removed e2e_tests/serverRootPath.config.ts, but its spec
(tests/login/serverRootPathRedirect.spec.ts) and the test_server_root_path.yml
workflow step still depend on it, so the redirect e2e job failed to load a
config that no longer existed.
2026-06-09 17:54:38 -07:00
ryan-crabbe-berri
248176112e
feat(ui): add admin flag to disable in-product UI nudges for everyone (#29796)
* feat(ui): add admin flag to disable in-product UI nudges for everyone

Admins can now suppress the survey and Claude Code feedback popups for
all users via a single disable_ui_nudges UI setting, instead of relying
on each user dismissing them individually.

* fix(ui): suppress nudges while ui settings are loading

Gate nudgesDisabled on the ui-settings loading state so an admin with
disable_ui_nudges on doesn't see the survey prompt flash, and the
getInProductNudgesCall fetch doesn't fire, on a cold page load before
the flag resolves. Falls back to showing nudges if the fetch errors.

* test(ui): wrap CreateKeyPage test in QueryClientProvider

page.tsx now calls useUISettings (react-query), which needs a
QueryClient that layout.tsx supplies in production but the test did
not. Add the provider and mock getUiSettings so the query resolves.
2026-06-09 17:45:42 -07:00
yuneng-jiang
50522157dc
docs(security): require a reproduction video for vulnerability reports (#30048) (#30063)
With AI models capable of automated vulnerability discovery now publicly
available, we expect a large increase in report volume, much of it
unverified. Requiring a video of the exploit running against a live
instance raises the bar for submissions and keeps triage focused on
reproducible issues. Reports without a video will be closed and reopened
if one is added later.

Co-authored-by: stuxf <70670632+stuxf@users.noreply.github.com>
2026-06-09 14:59:50 -07:00
tin-berri
5b7063d194
fix(mcp): allow team access-group grants in OAuth authorize/token access check (#30041)
* fix(mcp): honor team access-group grants in OAuth authorize/token access check

* test(mcp): mock build_effective_auth_contexts in non-admin authorize tests for isolation
2026-06-09 14:19:11 -07:00
tin-berri
d8fe091938
fix(ui/mcp): reset OAuth state on create-server modal close so a prior server's token no longer leaks into the next add-server session (#30000)
* fix(ui/mcp): reset OAuth hook state on modal close so a prior server's token no longer leaks into the next add-server session

* fix(ui/mcp): clear in-flight OAuth guard on reset and reset form/tools on modal close so nothing leaks on a parent-driven dismiss
2026-06-09 14:18:28 -07:00
ryan-crabbe-berri
38edf241a4
chore(ui): remove dead App Router route stubs under (dashboard) (#30045)
models-and-endpoints, organizations, and virtual-keys each had a page.tsx
route under (dashboard)/ that is not in MIGRATED_PAGES, so the sidebar and
deep links never resolve to it and the route is unreachable. Each was a thin
wrapper that handed the shared view empty or no-op props (empty modelData with
a no-op setModelData, hardcoded empty organizations, no-op
setUserRole/setUserEmail), so reaching one would render a degraded page in any
case. The real wrapper belongs in the PR that flips each page into
MIGRATED_PAGES, written with eyes on it and a test

This continues the dead-scaffolding cleanup from #28891. The shared components
these wrappers rendered (ModelsAndEndpointsView, OrganizationFilters) stay,
since the legacy ?page= switch in app/page.tsx and src/components still import
them
2026-06-09 14:05:09 -07:00
michelligabriele
fe60f9d0f1
fix(proxy): extend response headers hook to streaming, TTS, image gen, and pass-through (#24232)
* fix(proxy): extend response headers hook to streaming, TTS, image gen, and pass-through

* test: mock post_call_response_headers_hook in audio speech route tests
2026-06-09 22:10:23 +02:00
ryan-crabbe-berri
6ae8a509f0
test(ui): data-driven App Router migration E2E smoke (default + server-root-path) (#29974)
* test(ui): add a data-driven App Router migration E2E smoke

Add a growing Playwright smoke for migrated pages: for each segment it deep-links
to the path route, asserts the URL and that the dashboard shell rendered, then
clicks off to a legacy page and asserts navigation still works. Driven by
e2e_tests/fixtures/migratedPages.ts, so adding a page is one line.

Runs in two situations against the same proxy: the default mount (npm run
e2e:migration) and a non-root SERVER_ROOT_PATH mount (npm run e2e:migration:root).
globalSetup now logs in at `${SERVER_ROOT_PATH}/ui/login` so the admin storage
state is valid under a prefix. Seeded with api-reference; append the rest as their
migrations merge.

* test(ui): support headed slow-motion + watch pauses in the migration smoke

Honor SLOWMO in the server-root-path config (the default config already did),
and add an env-gated E2E_WATCH_MS pause so a headed run lingers on each state.
Both are no-ops by default, so CI behavior is unchanged.

* test(ui): make the migration smoke a sidebar-click user journey

Rework the smoke from deep-linking to a real navigation journey: start at the
landing page, click the migrated page in the sidebar (expanding submenus for
nested items), assert the path route rendered, reload it (the check a wrong
server_root_path breaks), bounce to a legacy page and back, and — once two pages
are migrated — navigate directly between two migrated pages. Verifies via URL +
shell render, driven by the same fixture list.

* test(ui): address review on the migration smoke

Escape ROOT and segment before interpolating them into RegExp URL matchers so a
future segment containing regex metacharacters can't silently widen the match.
Make the server-root-path config fail fast when SERVER_ROOT_PATH is unset instead
of silently re-running the default mount and passing without exercising the prefix.

* test(ui): drop unused watch helper and fix stale smoke README

* test(ui): run the migration smoke under a server root path in CI

* test(ui): harden + instrument the server-root-path proxy reboot in CI

* test(ui): run the server-root-path migration smoke as its own CI job

Replace the in-place proxy reboot in e2e_ui_testing with a dedicated
e2e_ui_testing_server_root_path job that boots the proxy once with
SERVER_ROOT_PATH=/litellm, matching how every other proxy variant in the
config gets its own job rather than killing and relaunching the live proxy.

The reboot was failing deterministically: after pkill -9 and relaunch the
prefixed proxy never came back up on :4000 (connection refused), so the smoke
never ran. The readiness step that was supposed to surface the cause could
never reach its boot-log tail because CircleCI runs steps under bash -eo
pipefail and the preceding `curl -sv ... | tail` aborted the step with curl's
exit 7. Booting the proxy as the job's own background step lets any boot crash
land in that step's log instead of being swallowed.

The default e2e_ui_testing job is unchanged aside from dropping the reboot,
prefixed-readiness, and prefixed-smoke steps; the migration smoke still runs at
the root mount there via the default Playwright config.
2026-06-09 10:40:01 -07:00
milan-berri
d84499e0f2
fix(team): reserve team budget raises for proxy admins on /team/update (#30030)
The caller's PERSONAL max_budget was the wrong yardstick for /team/update: a
team's spend ceiling has nothing to do with the admin's own key budget. That
comparison was an unintended side effect of reusing _check_user_team_limits()
(which exists for the /team/new path) and broke the UI, which re-sends the
unchanged budget on every save.

New behavior on /team/update for standalone teams:
- A team admin (already authorized via _verify_team_access) may freely KEEP or
  LOWER the team budget, and change models/tpm/rpm, without being gated by their
  personal limits.
- GROWING a team's spend ceiling is a budget-authority action reserved for proxy
  admins -> 403 for team admins. "Growing" covers both raising max_budget above
  the team's current finite value and removing the cap entirely (max_budget=null,
  detected via model_fields_set so an explicit null is distinguished from an
  omitted field). For a team that currently has no cap, setting a finite value is
  a restriction and is allowed.
- Org-scoped teams remain governed by _check_org_team_limits() (capped by the
  org budget).

Also reverts the #29525 existing_team_max_budget workaround in
_check_user_team_limits() back to the create-only form; /team/new still enforces
the creator's personal caps.

docs(access_control): resolve the contradiction in the team-admin section —
team admins can keep/lower the budget and manage rate limits/models, but cannot
raise the team budget (proxy-admin only).

tests: unit + behavior coverage for raise-blocked, cap-removal-blocked (team
admin), raise/removal allowed (proxy admin), uncapped-team restriction allowed,
keep/lower/resend allowed, and unchanged create-path guards.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-09 09:19:15 -07:00