mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-06 02:48:13 +00:00
fix(mcp-oauth2): apply _extract_access_token in _check_byok_credential
_check_byok_credential wrote the raw credential from DB directly to
_byok_cred_cache without calling _extract_access_token. When the OAuth2
callback stores a JSON blob {"access_token": "...", "refresh_token": "..."},
a subsequent call that went through _check_byok_credential first (rather
than _get_byok_credential) would populate the cache with the blob. The
next _get_byok_credential call would return the blob as the Bearer token,
causing silent HTTP 401s on every upstream API call.
Fix: extract the access_token before writing to cache, consistent with
how _get_byok_credential already handles it.
This commit is contained in:
parent
19ab870f32
commit
12880bf760
1 changed files with 6 additions and 1 deletions
|
|
@ -1651,11 +1651,16 @@ if MCP_AVAILABLE:
|
|||
if prisma_client is None:
|
||||
return
|
||||
|
||||
credential = await get_user_credential(
|
||||
raw_credential = await get_user_credential(
|
||||
prisma_client=prisma_client,
|
||||
user_id=user_id,
|
||||
server_id=mcp_server.server_id,
|
||||
)
|
||||
# Apply _extract_access_token so the cache always stores a plain token
|
||||
# string. Without this, a JSON blob {"access_token": ..., "refresh_token": ...}
|
||||
# stored by the OAuth2 callback would be returned as-is by _get_byok_credential
|
||||
# on the next request, causing Bearer-header corruption and silent 401s.
|
||||
credential = _extract_access_token(raw_credential)
|
||||
_write_byok_cred_cache(user_id, mcp_server.server_id, credential)
|
||||
if credential is None:
|
||||
raise HTTPException(
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue