* fix(mcp): respect X-Forwarded-Proto header in OAuth endpoints When LiteLLM proxy is deployed behind a reverse proxy (like nginx or a load balancer) that terminates SSL/TLS, the proxy receives HTTP requests internally but should expose HTTPS URLs externally. This change detects the X-Forwarded-Proto header and uses it to construct correct redirect URIs and endpoint URLs. Changes: - Added X-Forwarded-Proto detection to authorize, token, oauth_protected_resource_mcp, oauth_authorization_server_mcp, and register_client endpoints - Added comprehensive tests for X-Forwarded-Proto header support across all affected endpoints - Fixed existing tests to properly mock request.headers 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * fix formatting * feat(mcp): support X-Forwarded-Host for proxy base URL reconstruction Extended X-Forwarded-Proto support to also handle X-Forwarded-Host and X-Forwarded-Port headers. This allows LiteLLM to correctly construct redirect URIs and endpoint URLs when deployed behind a reverse proxy that changes the host/port. Example scenario: - Internal URL: http://localhost:8888/github/mcp - External URL: https://proxy.abc.com/github/mcp - Proxy sets: X-Forwarded-Proto: https, X-Forwarded-Host: proxy.abc.com Changes: - Added get_request_base_url() helper function to centralize X-Forwarded-* header handling - Replaced all inline X-Forwarded-Proto checks with calls to the helper function - Helper handles X-Forwarded-Proto, X-Forwarded-Host, and X-Forwarded-Port - Added tests for X-Forwarded-Host scenarios in authorize and token endpoints Fixes issue where protected resource URL mismatch occurred: Error: Protected resource http://proxy.abc.com:8888/github/mcp does not match expected https://proxy.abc.com/github/mcp 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * chore: replace Yelp-specific hostnames with generic examples Changed all references from chatproxy.yelpcorp.com to proxy.example.com in: - test_proxy_forwarding.py (default host parameter) - TEST_PROXY_FORWARDING.md (documentation examples) - discoverable_endpoints.py (docstring example) - test_discoverable_endpoints.py (test mock data) This makes the code more generic and suitable for open source. All 13 tests still passing. * remove accidentally added files * fix formatting * add new test for get_base_url --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| caching | ||
| completion_extras/litellm_responses_transformation | ||
| enterprise/enterprise_callbacks | ||
| experimental_mcp_client | ||
| google_genai | ||
| integrations | ||
| litellm_core_utils | ||
| llms | ||
| passthrough | ||
| proxy | ||
| responses | ||
| router_strategy | ||
| router_utils | ||
| secret_managers | ||
| types | ||
| vector_stores | ||
| __init__.py | ||
| conftest.py | ||
| log.txt | ||
| readme.md | ||
| test_acompletion_session_reuse_e2e.py | ||
| test_aembedding_session_reuse_e2e.py | ||
| test_azure_video_router.py | ||
| test_constants.py | ||
| test_cost_calculation_log_level.py | ||
| test_cost_calculator.py | ||
| test_exception_mapping_request_attribute.py | ||
| test_filter_out_litellm_params.py | ||
| test_groq_streaming_encoding.py | ||
| test_logging.py | ||
| test_lowest_latency_zero_tokens.py | ||
| test_main.py | ||
| test_redis.py | ||
| test_responses_id_security.py | ||
| test_router_google_genai.py | ||
| test_router.py | ||
| test_shared_session_integration.py | ||
| test_system_message_format_bug.py | ||
| test_utils.py | ||
| test_uuid_helper.py | ||
| test_video_generation.py | ||
Testing for litellm/
This directory 1:1 maps the the litellm/ directory, and can only contain mocked tests.
The point of this is to:
- Increase test coverage of
litellm/ - Make it easy for contributors to add tests for the
litellm/package and easily run tests without needing LLM API keys.
File name conventions
litellm/proxy/test_caching_routes.pymaps tolitellm/proxy/caching_routes.pytest_<filename>.pymaps tolitellm/<filename>.py