Sync packaging to live v1.84.0 deployment (CVE-2026-35029/59822 fix line)
- Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating main-v1.74.0-stable, which silently moved to a newer digest). v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth bypass, fixed 1.84.0, CISA KEV). - Drop the v1.74.0-era sed CORS patch: upstream v1.84.0 moved the file and now reads LITELLM_CORS_ORIGINS natively. - start.sh: export LITELLM_CORS_ORIGINS (the native v1.84.0 var) instead of LITELLM_CORS_ALLOWED_ORIGINS (the old sed-patch var that v1.84.0 ignores) — keeps CORS locked to chat.inference.coop. - CloudronManifest: upstreamVersion 1.74.0 -> 1.84.0. Live gateway already runs v1.84.0 (image digest sha256:dc532d896ba8..., built 2026-10-02 04:50 UTC); this commit makes the repo mirror the deployed packaging per the no-drift rule. LITELLM_CORS_ORIGINS also set as a Cloudron env var on the app so the running container honours it without a rebuild.
This commit is contained in:
1 parent
8f42be988e
commit
fd34e33508
3 files changed
+18
-14
No files matched your search
@@ -77,11 +77,13 @@ export NO_OPENAPI="True"
|
||||
# Proxy settings for Cloudron's reverse proxy
|
||||
export LITELLM_PROXY_BASE_URL="https://${CLOUDRON_APP_DOMAIN}"
|
||||
|
||||
# CORS: lock browser access to the co-op's own chat origin. The gateway is
|
||||
# called server-to-server (chat → portal → gateway) and by member API keys
|
||||
# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here (the old
|
||||
# fallback) would let any website's JS hit the gateway.
|
||||
export LITELLM_CORS_ALLOWED_ORIGINS="https://chat.inference.coop"
|
||||
# CORS: LiteLLM v1.84.0 reads LITELLM_CORS_ORIGINS natively (upstream added
|
||||
# the env var in place of the old hardcoded `origins = ["*"]`). Lock browser
|
||||
# access to the co-op's own chat origin. The gateway is called
|
||||
# server-to-server (chat → portal → gateway) and by member API keys
|
||||
# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here would let
|
||||
# any website's JS hit the gateway.
|
||||
export LITELLM_CORS_ORIGINS="https://chat.inference.coop"
|
||||
|
||||
echo "PostgreSQL: ${CLOUDRON_POSTGRESQL_HOST}:${CLOUDRON_POSTGRESQL_PORT}"
|
||||
echo "Redis: ${CLOUDRON_REDIS_HOST}:${CLOUDRON_REDIS_PORT}"
|
||||
|
||||
Reference in new issue
Block a user