From 427d013d8cf4bef182e2ef8e26d156a18d328bf6 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 6 Mar 2026 14:48:23 -0800 Subject: [PATCH] add credential absence assertions to test_pkce_token_exchange_basic_auth Verify that client_id and client_secret are NOT double-sent in the POST body when Basic Auth is used (include_client_id=False with client_secret). Catches regressions where credentials leak into both Auth header and body. --- tests/test_litellm/proxy/management_endpoints/test_ui_sso.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index d9473072053..9b585d49447 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -3423,6 +3423,10 @@ class TestPKCEFunctionality: assert isinstance(kwargs["auth"], httpx.BasicAuth) # Verify code_verifier is in the POST body (essential PKCE field) assert kwargs.get("data", {}).get("code_verifier") == "verifier_abc" + # Verify credentials are NOT double-sent in the POST body when using Basic Auth + post_data = kwargs.get("data", {}) + assert "client_secret" not in post_data, "client_secret must not appear in POST body when using Basic Auth" + assert "client_id" not in post_data, "client_id must not appear in POST body when using Basic Auth (include_client_id=False)" return mock_response # Use separate mock clients for token exchange and userinfo —