mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-20 00:11:50 +00:00
The dashboard had two parallel auth systems: AuthContext (provided at the
root, used by the legacy ?page= shell) and useAuthorized (used by ~85 files
in the migrated tree), each reading the cookie, decoding the JWT, and
deciding when to redirect on its own. Only AuthContext applied the decoded
auth_header_name via setGlobalLitellmHeaderName, so the two trees could
disagree on custom auth headers, and each ran its own login-redirect effect
AuthContext stays the engine: it still resolves uiConfig before clearing
authLoading (so proxy-rooted URLs are correct) and performs the single
decode. useAuthorized now consumes the context and only layers on policy:
the admin_ui_disabled check and the redirect-to-login side effect. Its
return shape is unchanged, so none of the ~85 consumers are touched
Context semantics are aligned to what the hook's consumers already
expected: userRole defaults to formatUserRole("") instead of "", and
showSSOBanner is computed strictly from login_method (default false)
instead of defaulting to true. The context's unused public setters
(setToken, setUserID, setAccessToken, setPremiumUser, setShowSSOBanner)
are dropped from the exported surface; only setUserRole/setUserEmail have
consumers. Decoded-JWT fields keep their legacy `any` typing at the hook
boundary since ~25 call sites rely on it; tightening is a follow-up
The hook's tests now exercise the real provider + hook together with real
JWTs instead of mocking the decode away, which also covers the provider's
expiry and undecodable-token paths
|
||
|---|---|---|
| .. | ||
| litellm-dashboard | ||
| Dockerfile | ||
| nginx.conf | ||