diff --git a/CloudronManifest.json b/CloudronManifest.json index be27812..256ab41 100644 --- a/CloudronManifest.json +++ b/CloudronManifest.json @@ -5,7 +5,7 @@ "description": "LiteLLM AI Gateway — OpenAI-compatible proxy with per-user API keys, usage tracking, rate limiting, and model routing. Packaged for Cloudron with SSO/OIDC and PostgreSQL.", "tagline": "AI gateway for cooperative inference", "version": "1.0.0", - "upstreamVersion": "1.74.0", + "upstreamVersion": "1.84.0", "healthCheckPath": "/health/readiness", "httpPort": 4000, "manifestVersion": 2, diff --git a/Dockerfile b/Dockerfile index 469c595..99fa8ef 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,9 @@ -FROM ghcr.io/berriai/litellm:main-v1.74.0-stable +FROM ghcr.io/berriai/litellm:v1.84.0 + +# v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on +# /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth +# bypass, fixed 1.84.0, CISA KEV catalog). Pin the exact tag — do NOT +# use a floating tag like main-v1.74.0-stable, which silently moved. # LiteLLM's official image runs as root. Cloudron's sandboxing (read-only # rootfs, AppArmor, dropped capabilities) still applies to root inside the @@ -19,10 +24,7 @@ COPY config.yaml /app/data/config.yaml # startup script runs instead of being passed as an argument to litellm. ENTRYPOINT ["/app/code/start.sh"] -# LiteLLM v1.74.0 hardcodes `origins = ["*"]` (with allow_credentials=True) in -# proxy_server.py and ignores LITELLM_CORS_ALLOWED_ORIGINS entirely. Rewrite it -# to honour the env var so we can lock CORS to the chat origin. Patch every copy -# (site-packages is what the running CLI imports; /app/litellm is a dev copy). -RUN sed -i 's/^origins = \["\*"\]$/import os; origins = os.getenv("LITELLM_CORS_ALLOWED_ORIGINS", "*").split(",")/' \ - /usr/lib/python3.13/site-packages/litellm/proxy/proxy_server.py \ - /app/litellm/proxy/proxy_server.py +# No CORS patch needed since v1.84.0: upstream replaced the hardcoded +# `origins = ["*"]` with a native LITELLM_CORS_ORIGINS env var (start.sh +# exports it). The old sed patch targeted a v1.74.0 file layout that no +# longer exists — the v1.84.0 rebuild self-skipped it correctly. diff --git a/start.sh b/start.sh index 2930ca4..4168295 100644 --- a/start.sh +++ b/start.sh @@ -77,11 +77,13 @@ export NO_OPENAPI="True" # Proxy settings for Cloudron's reverse proxy export LITELLM_PROXY_BASE_URL="https://${CLOUDRON_APP_DOMAIN}" -# CORS: lock browser access to the co-op's own chat origin. The gateway is -# called server-to-server (chat → portal → gateway) and by member API keys -# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here (the old -# fallback) would let any website's JS hit the gateway. -export LITELLM_CORS_ALLOWED_ORIGINS="https://chat.inference.coop" +# CORS: LiteLLM v1.84.0 reads LITELLM_CORS_ORIGINS natively (upstream added +# the env var in place of the old hardcoded `origins = ["*"]`). Lock browser +# access to the co-op's own chat origin. The gateway is called +# server-to-server (chat → portal → gateway) and by member API keys +# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here would let +# any website's JS hit the gateway. +export LITELLM_CORS_ORIGINS="https://chat.inference.coop" echo "PostgreSQL: ${CLOUDRON_POSTGRESQL_HOST}:${CLOUDRON_POSTGRESQL_PORT}" echo "Redis: ${CLOUDRON_REDIS_HOST}:${CLOUDRON_REDIS_PORT}"