fix: forward OAuth error params in callback, fix BYOK guard exception handling in db.py

This commit is contained in:
Ishaan Jaffer 2026-03-11 09:23:44 -07:00
parent c9f834f093
commit 0bd002c852
2 changed files with 12 additions and 8 deletions

View file

@ -506,17 +506,17 @@ async def store_user_oauth_credential(
where={"user_id_server_id": {"user_id": user_id, "server_id": server_id}}
)
if existing is not None:
_byok_error = ValueError(
f"A non-OAuth2 credential already exists for user {user_id} "
f"and server {server_id}. Refusing to overwrite."
)
try:
raw = json.loads(base64.urlsafe_b64decode(existing.credential_b64).decode())
if raw.get("type") != "oauth2":
raise ValueError(
f"A non-OAuth2 credential already exists for user {user_id} "
f"and server {server_id}. Refusing to overwrite."
)
except (ValueError, KeyError):
raise
except Exception:
pass # Malformed existing record — allow overwrite
# Credential is not base64+JSON — it's a plain-text BYOK key.
raise _byok_error
if raw.get("type") != "oauth2":
raise _byok_error
encoded = base64.urlsafe_b64encode(json.dumps(payload).encode()).decode()
await prisma_client.db.litellm_mcpusercredentials.upsert(

View file

@ -36,6 +36,10 @@ const McpOAuthCallbackContent = () => {
type: "litellm-mcp-oauth",
code: searchParams.get("code"),
state: searchParams.get("state"),
// Forward OAuth provider error params so the hook can surface the real
// reason (e.g. "access_denied") instead of a generic "code missing" error.
error: searchParams.get("error"),
error_description: searchParams.get("error_description"),
};
}, [searchParams]);