litellm/ui/litellm-dashboard/src/hooks
Yuneng Jiang f1383f16fa
refactor(ui): route MCP session tokens through the shared storage helper
mcpTokenStore was the only OAuth path writing straight to window.sessionStorage;
useMcpOAuthFlow, useToolsOAuthFlow, the callback page and the edit-screen UI state
all already go through secureStorage. Align it so the OAuth surface has one storage
format instead of two.

The stored payload also carried a refresh_token that nothing ever read back. All
three read sites take access_token only, and nothing reads the mcp-session-token:
keys directly, so the field was write-only. Drop it from the store and from the four
callers that populated it. The client-forwarded modes (true_passthrough and
oauth_delegate) re-authorize rather than refresh, and authorization_code is
unaffected because it persists through storeMCPOAuthUserCredential on the backend,
which keeps its own refresh token.

Entries written before this change decode to null and are treated as absent, which
surfaces the normal Authorize prompt; they are session-scoped and expire in an hour.

Add two regression tests that decode the stored value before asserting, so neither
can pass merely because the payload is no longer plain text.
2026-08-04 14:15:29 -07:00
..
policies style(ui): run prettier --write across the dashboard (#29622) 2026-06-04 11:37:54 -07:00
mcpOAuthUtils.ts fix(mcp): let non-creator users OAuth into OBO-mode MCP servers from the Tools page (#29867) 2026-06-08 13:35:49 -07:00
use-safe-layout-effect.ts added and ran prettier autoformatter 2025-10-04 18:19:48 -07:00
useMcpOAuthFlow.test.tsx fix(mcp): persist DCR client_id from on-create MCP OAuth Authorize & Fetch (#31920) 2026-07-03 12:15:33 -07:00
useMcpOAuthFlow.tsx fix(mcp): mint an ephemeral OAuth client when passthrough authorize has no client_id 2026-07-22 18:03:58 -07:00
useTestMCPConnection.tsx refactor(ui): useTestMCPConnection uses the shared isClientForwardedTokenMode helper 2026-07-09 13:51:03 -07:00
useToolsOAuthFlow.test.tsx fix(mcp): mint an ephemeral OAuth client when passthrough authorize has no client_id 2026-07-22 18:03:58 -07:00
useToolsOAuthFlow.tsx refactor(ui): route MCP session tokens through the shared storage helper 2026-08-04 14:15:29 -07:00
useUserMcpOAuthFlow.tsx style(ui): run prettier --write across the dashboard (#29622) 2026-06-04 11:37:54 -07:00
useVisitedTabs.ts fix(ui): keep tab panel state across tab switches on the migrated routes 2026-07-23 23:16:34 -07:00
useWorker.ts style(ui): run prettier --write across the dashboard (#29622) 2026-06-04 11:37:54 -07:00