mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-15 23:31:29 +00:00
litellm already supports Google, Microsoft and generic OIDC SSO through fastapi-sso, which has no SAML support; AuthMethod.SAML existed only as an unused enum value. This adds real SAML 2.0 single sign-on for the admin UI. A new SAMLAuthHandler validates signed assertions with the OneLogin python3-saml toolkit and maps them onto a CustomOpenID, then reuses the shared post-login path every other provider goes through, so provisioning, role/team mapping and the UI session JWT are unchanged. Both SP-initiated and IdP-initiated HTTP-POST flows are supported. SP-initiated logins are bound to the browser that started them via an HttpOnly state cookie plus a cached AuthnRequest id, and the ACS rejects any response whose InResponseTo doesn't match; unsolicited (IdP-initiated) responses cannot be browser-bound so they are rejected unless SAML_ALLOW_UNSOLICITED=true. Replays are rejected by a consumed-assertion guard whose lifetime tracks each assertion's NotOnOrAfter, and both the replay guard and the login-state binding go through the proxy's shared in-memory + Redis cache for multi-instance deployments. The ACS honors DISABLE_ADMIN_UI and re-applies the free-SSO-user Enterprise gate after the assertion is validated, so an unvalidated POST can no longer drive the billable-user count query. SAML is configurable from the admin UI SSO settings (IdP metadata URL or inline XML, SP entity ID, and an allow-unsolicited toggle), which persists the SAML_* environment variables the handler reads, exactly like the Google, Microsoft and generic OIDC providers. python3-saml is kept as an optional saml extra; its xmlsec and lxml wheels bundle the native libraries so no system packages are required, and the import is guarded so the proxy still starts without the package with the SAML routes returning a clear 501. Resolves LIT-4016 |
||
|---|---|---|
| .. | ||
| public | ||
| scripts | ||
| src | ||
| tests | ||
| .env.development | ||
| .env.production | ||
| .npmrc | ||
| .nvmrc | ||
| .prettierignore | ||
| .prettierrc | ||
| build_release_ui.sh | ||
| build_ui.sh | ||
| build_ui_custom_path.sh | ||
| CLAUDE.md | ||
| components.json | ||
| eslint-budgets.json | ||
| eslint-suppressions.json | ||
| eslint.config.mjs | ||
| knip.json | ||
| next.config.mjs | ||
| package-lock.json | ||
| package.json | ||
| postcss.config.js | ||
| README.md | ||
| tsconfig.json | ||
| tsconfig.tsbuildinfo | ||
| vitest.config.ts | ||
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Inter, a custom Google Font.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.