From 50631f895945bea60bb505992821a2777a34a6d6 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Thu, 5 Mar 2026 12:04:01 -0800 Subject: [PATCH] fix: address second round of greptile review feedback - Fix PKCE error hint: check env var directly (not code_verifier presence) to distinguish 'PKCE not configured' from 'PKCE enabled but cache miss' - Fix misleading Redis TTL comment in proxy_server.py --- litellm/proxy/management_endpoints/ui_sso.py | 11 +++++++---- litellm/proxy/proxy_server.py | 2 +- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index f86da969c26..76691ee569d 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -830,10 +830,13 @@ async def get_generic_sso_response( except Exception as e: error_message = str(e) - # Only surface "enable PKCE" advice when PKCE was NOT already in use. - # If code_verifier is set, the token exchange itself failed — that's a - # provider-side error, not a configuration problem. - if code_verifier is None and ( + # Surface a helpful PKCE misconfiguration hint only when: + # 1. The error mentions PKCE/code verifier, AND + # 2. PKCE is not currently configured (GENERIC_CLIENT_USE_PKCE != true) + # If PKCE IS configured but code_verifier was absent (cross-instance cache miss), + # the real fix is shared Redis/sticky sessions — not enabling PKCE (it's already on). + pkce_configured = os.getenv("GENERIC_CLIENT_USE_PKCE", "false").lower() == "true" + if not pkce_configured and ( "PKCE" in error_message or "code verifier" in error_message.lower() ): is_okta = ( diff --git a/litellm/proxy/proxy_server.py b/litellm/proxy/proxy_server.py index 14d0bbd889e..b52e64a8161 100644 --- a/litellm/proxy/proxy_server.py +++ b/litellm/proxy/proxy_server.py @@ -3030,7 +3030,7 @@ class ProxyConfig: if user_api_key_cache_ttl is not None: user_api_key_cache.update_cache_ttl( default_in_memory_ttl=float(user_api_key_cache_ttl), - default_redis_ttl=None, # will be set below if Redis is available + default_redis_ttl=None, # PKCE verifiers set explicit TTL on each store; Redis TTL not configured here ) ### CONFIGURE USER API KEY CACHE TO USE REDIS FOR PKCE (if enabled) ###