Lock CORS to chat origin (was wildcard * with allow-credentials)

This commit is contained in:
inference-bot committed 2026-09-14 17:51:38 -06:00
1 parent fb921b6e09
commit dae9bf4f31
1 file changed
+5 -2
+5 -2
View File
@@ -77,8 +77,11 @@ export NO_OPENAPI="True"
# Proxy settings for Cloudron's reverse proxy # Proxy settings for Cloudron's reverse proxy
export LITELLM_PROXY_BASE_URL="https://${CLOUDRON_APP_DOMAIN}" export LITELLM_PROXY_BASE_URL="https://${CLOUDRON_APP_DOMAIN}"
# Allow requests from Cloudron's Open WebUI, LobeChat, etc. # CORS: lock browser access to the co-op's own chat origin. The gateway is
export LITELLM_CORS_ALLOWED_ORIGINS="${CLOUDRON_WEB_ORIGIN:-*}" # called server-to-server (chat → portal → gateway) and by member API keys
# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here (the old
# fallback) would let any website's JS hit the gateway.
export LITELLM_CORS_ALLOWED_ORIGINS="https://chat.inference.coop"
echo "PostgreSQL: ${CLOUDRON_POSTGRESQL_HOST}:${CLOUDRON_POSTGRESQL_PORT}" echo "PostgreSQL: ${CLOUDRON_POSTGRESQL_HOST}:${CLOUDRON_POSTGRESQL_PORT}"
echo "Redis: ${CLOUDRON_REDIS_HOST}:${CLOUDRON_REDIS_PORT}" echo "Redis: ${CLOUDRON_REDIS_HOST}:${CLOUDRON_REDIS_PORT}"