* fix(mcp): respect X-Forwarded-Proto header in OAuth endpoints When LiteLLM proxy is deployed behind a reverse proxy (like nginx or a load balancer) that terminates SSL/TLS, the proxy receives HTTP requests internally but should expose HTTPS URLs externally. This change detects the X-Forwarded-Proto header and uses it to construct correct redirect URIs and endpoint URLs. Changes: - Added X-Forwarded-Proto detection to authorize, token, oauth_protected_resource_mcp, oauth_authorization_server_mcp, and register_client endpoints - Added comprehensive tests for X-Forwarded-Proto header support across all affected endpoints - Fixed existing tests to properly mock request.headers 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * fix formatting * feat(mcp): support X-Forwarded-Host for proxy base URL reconstruction Extended X-Forwarded-Proto support to also handle X-Forwarded-Host and X-Forwarded-Port headers. This allows LiteLLM to correctly construct redirect URIs and endpoint URLs when deployed behind a reverse proxy that changes the host/port. Example scenario: - Internal URL: http://localhost:8888/github/mcp - External URL: https://proxy.abc.com/github/mcp - Proxy sets: X-Forwarded-Proto: https, X-Forwarded-Host: proxy.abc.com Changes: - Added get_request_base_url() helper function to centralize X-Forwarded-* header handling - Replaced all inline X-Forwarded-Proto checks with calls to the helper function - Helper handles X-Forwarded-Proto, X-Forwarded-Host, and X-Forwarded-Port - Added tests for X-Forwarded-Host scenarios in authorize and token endpoints Fixes issue where protected resource URL mismatch occurred: Error: Protected resource http://proxy.abc.com:8888/github/mcp does not match expected https://proxy.abc.com/github/mcp 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * chore: replace Yelp-specific hostnames with generic examples Changed all references from chatproxy.yelpcorp.com to proxy.example.com in: - test_proxy_forwarding.py (default host parameter) - TEST_PROXY_FORWARDING.md (documentation examples) - discoverable_endpoints.py (docstring example) - test_discoverable_endpoints.py (test mock data) This makes the code more generic and suitable for open source. All 13 tests still passing. * remove accidentally added files * fix formatting * add new test for get_base_url --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| _experimental/mcp_server | ||
| anthropic_endpoints | ||
| auth | ||
| client | ||
| common_utils | ||
| db | ||
| experimental/mcp_server | ||
| google_endpoints | ||
| guardrails | ||
| health_endpoints | ||
| hooks | ||
| image_endpoints | ||
| management_endpoints | ||
| management_helpers | ||
| middleware | ||
| openai_files_endpoint | ||
| pass_through_endpoints | ||
| response_api_endpoints | ||
| spend_tracking | ||
| test_configs | ||
| ui_crud_endpoints | ||
| vector_store_endpoints | ||
| __init__.py | ||
| test_batch_metadata_none_fix.py | ||
| test_caching_routes.py | ||
| test_common_request_processing.py | ||
| test_custom_proxy.py | ||
| test_fastapi_offline_routes.py | ||
| test_health_check_functions.py | ||
| test_litellm_pre_call_utils.py | ||
| test_proxy_cli.py | ||
| test_proxy_server.py | ||
| test_proxy_types.py | ||
| test_proxy_utils.py | ||
| test_route_llm_request.py | ||
| test_shared_health_check.py | ||
| test_spend_log_cleanup.py | ||
| test_swagger_chat_completions.py | ||
| test_team_member_update.py | ||