litellm/tests/test_litellm/proxy/common_utils
yucheng-berri 5637b3212e
feat(proxy): configurable response headers and login-page hint (#30792)
* feat(proxy): add configurable response headers middleware

Adds a small ASGI middleware that sets standard response headers
(X-Frame-Options, Content-Security-Policy frame-ancestors, X-Content-Type-Options)
on proxy and UI responses. Strict-Transport-Security is optional and gated
behind LITELLM_ENABLE_HSTS for HTTPS deployments. Values use setdefault so a
route that sets its own header is preserved.

* feat(proxy/ui): make login page credentials hint configurable

build_ui_login_form accepts a hide_default_credentials_hint parameter and
google_login reads LITELLM_HIDE_DEFAULT_CREDENTIALS_HINT (or general_settings)
so the legacy login page behaves consistently with the new UI. Also collapses
a duplicated branch and removes an unused variable and module-level constant.

* fix(proxy/ui): apply credentials hint flag on /fallback/login

The /fallback/login handler still rendered the default-credentials hint
regardless of LITELLM_HIDE_DEFAULT_CREDENTIALS_HINT. Collapse its duplicate
branch and forward the flag, matching google_login, so all login surfaces
behave consistently. Adds regression tests for /fallback/login and makes the
ui_sso test helper restore os.environ so env vars do not leak across tests.
2026-06-18 18:12:45 -07:00
..
html_forms feat(proxy): configurable response headers and login-page hint (#30792) 2026-06-18 18:12:45 -07:00
test_cache_codec.py
test_callback_utils.py
test_custom_openapi_spec.py
test_expired_ui_session_key_cleanup_manager.py
test_get_routes.py
test_http_parsing_utils.py
test_key_rotation_e2e.py
test_key_rotation_integration.py
test_key_rotation_lock.py
test_key_rotation_manager.py
test_load_config_utils.py
test_openai_endpoint_utils.py
test_path_utils.py
test_reset_budget_job.py
test_static_asset_utils.py
test_timezone_utils.py
test_upsert_budget_membership.py
test_user_api_key_cache.py