Skip to content

fix(ui): resolve login redirect loop when reverse proxy adds HttpOnly to cookies - #23532

Merged
krrish-berri-2 merged 32 commits into
BerriAI:litellm_oss_staging_04_04_2026from
jaxhend:litellm_login_httponly_cookie_fix
Apr 6, 2026
Merged

fix(ui): resolve login redirect loop when reverse proxy adds HttpOnly to cookies#23532
krrish-berri-2 merged 32 commits into
BerriAI:litellm_oss_staging_04_04_2026from
jaxhend:litellm_login_httponly_cookie_fix

Merge branch 'BerriAI:main' into litellm_login_httponly_cookie_fix

3298858
Select commit
Loading
Failed to load commit list.
GitGuardian / GitGuardian Security Checks failed Apr 6, 2026 in 1m 2s

3 secrets uncovered!

3 secrets were uncovered from the scan of 32 commits in your pull request. ❌

Please have a look to GitGuardian findings and remediate in order to secure your code.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

Details

🔎 Detected hardcoded secrets in your pull request

  • Pull request #23532: litellm_login_httponly_cookie_fix 👉 litellm_oss_staging_04_04_2026
GitGuardian id GitGuardian status Secret Commit Filename
29203054 Triggered Generic High Entropy Secret eb1a83e tests/test_litellm/test_secret_redaction.py View secret
29203056 Triggered Generic High Entropy Secret eb1a83e tests/test_litellm/test_secret_redaction.py View secret
29375658 Triggered JSON Web Token 3298858 tests/test_litellm/proxy/auth/test_handle_jwt.py View secret

🛠 Guidelines to remediate hardcoded secrets

  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.