From 1bddacfb68baaff8888675333717c2c627e2c3c4 Mon Sep 17 00:00:00 2001 From: yucheng Date: Wed, 30 Sep 2026 02:25:58 +0000 Subject: [PATCH] fix(guardrails): stop pointing admins at the removed resource_app_id in the connect-time 503 Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../proxy/guardrails/guardrail_hooks/agent_365/agent_365.py | 2 +- .../proxy/guardrails/guardrail_hooks/test_agent_365.py | 3 +++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py index 9ffd1111d62..6e5849a92a4 100644 --- a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py +++ b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py @@ -508,7 +508,7 @@ class Agent365Guardrail(CustomGuardrail): return Unavailable( detail=( f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); " - "check the guardrail's client_id, client_secret and resource_app_id" + "check the guardrail's client_id and client_secret" ), fail_open=self.unreachable_fallback == "fail_open", ) diff --git a/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py b/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py index a43ffd34145..fd2f14471ce 100644 --- a/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py +++ b/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py @@ -1280,6 +1280,9 @@ class TestPreflightCallerSignIn: assert isinstance(verdict, Unavailable) assert verdict.fail_open is False assert "bad client_secret" in verdict.detail + assert "resource_app_id" not in verdict.detail, ( + "the field was removed from the config; do not tell admins to check it" + ) @pytest.mark.asyncio async def test_endpoint_unreachable_fail_open_is_unavailable(self):