Per-LLMClient CORS Origins

Per-LLMClient CORS origins.

A web page that embeds Smarter Chat (the @smarter.sh/ui-chat npm package) calls its LLMClient’s configuration and prompt apis from the browser, cross-origin, with credentials. The platform’s CORS settings (CORS_ALLOWED_ORIGINS and CORS_ALLOWED_ORIGIN_REGEXES) allow the platform’s own origins. An LLMClient’s manifest can allow more, in spec.config.allowedOrigins, which this module applies, through django-cors-headers’ check_request_enabled signal: a receiver that returns True allows the request’s origin, for preflight requests and for the requests themselves.

Only the apis that Smarter Chat calls are considered:

  • a deployed LLMClient’s own host (or custom domain): /, /config/ and /prompt/,

  • the platform api: /api/v1/llm-clients/<hashed_id or id>/config/, .../prompt/ and .../prompt/config/.

smarter.apps.llmclient.cors.allow_llmclient_origins(sender, request, **kwargs)[source]

Allow a cross-origin request whose origin its LLMClient’s manifest allows.

Called by django-cors-headers for each request whose origin the platform’s CORS settings don’t allow. It never raises: a request that can’t be resolved is simply not allowed here.

Parameters:
  • sender – None.

  • request (HttpRequest) – The request.

Returns:

True to allow the request’s origin.

Return type:

bool

smarter.apps.llmclient.cors.llmclient_for_cors(request)[source]

The LLMClient whose configuration or prompt api the request calls, if any.

Parameters:

request (HttpRequest) – The request, which may be a CORS preflight request.

Returns:

The LLMClient, or None if the request isn’t for one of its apis.

Return type:

LLMClient | None

smarter.apps.llmclient.cors.origin_allowed(origin, llmclient)[source]

Whether the LLMClient allows the origin.

Parameters:
  • origin (str | None) – The request’s Origin header.

  • llmclient (LLMClient | None) – The LLMClient.

Returns:

True if the origin is in the LLMClient’s allowed_origins.

Return type:

bool