From 4022928ac768df4fc8583eda0aa4bb21934db7a9 Mon Sep 17 00:00:00 2001 From: jesus Date: Thu, 17 Sep 2026 02:06:58 +0000 Subject: [PATCH] fix(mcp): suppress BLE001 on deliberate broad state-decode catch in /callback Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../proxy/_experimental/mcp_server/discoverable_endpoints.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py index e8f864a136c..5bdcfe5be20 100644 --- a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py @@ -2243,7 +2243,7 @@ async def callback( encoded_state = _resolve_encoded_oauth_state(request, state) try: state_data = decode_state_hash(encoded_state) - except Exception: + except Exception: # noqa: BLE001 # any decode failure means the session is unusable; surface it, never crash the callback cookie_present: Final = _oauth_state_cookie_present(request, state) verbose_logger.warning( "MCP /callback could not decode OAuth state (state_cookie_present=%s, request_base_url=%s, "