mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-24 00:52:24 +00:00
Password login now stamps login_method=username_password into the UI session key metadata, and change_password rejects any caller that is not a litellm-dashboard key carrying that marker with 403 before the user row is read. SSO sessions and user-associated virtual keys can no longer use the endpoint as a current_password guessing oracle. The forced-reset session is still minted by the password login path, so it keeps access to the endpoint Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| litellm-dashboard | ||
| Dockerfile | ||
| nginx.conf | ||