Merge pull request #24706 from BerriAI/litellm_fix-jwt-none-guard

fix(auth): guard JWTHandler.is_jwt() against None token
This commit is contained in:
ryan-crabbe-berri 2026-03-27 18:06:24 -07:00 • committed by GitHub
commit 5b651048f2
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 10 additions and 1 deletions

View file

@ -89,7 +89,9 @@ class JWTHandler:
self.leeway = leeway
@staticmethod
def is_jwt(token: str):
def is_jwt(token: Optional[str]) -> bool:
if token is None:
return False
parts = token.split(".")
return len(parts) == 3

View file

@ -1331,6 +1331,9 @@ def test_jwt_handler_is_jwt_static_method():
# Test with empty string
assert JWTHandler.is_jwt("") == False
# Test with None (missing Authorization header)
assert JWTHandler.is_jwt(None) == False
@pytest.mark.parametrize(
"requested_model, should_work",

View file

@ -567,6 +567,10 @@ class TestJWTOAuth2Coexistence:
assert JWTHandler.is_jwt("Bearer token") is False
assert JWTHandler.is_jwt("two.parts") is False
def test_is_jwt_returns_false_for_none(self):
"""None token (missing Authorization header) should not be treated as JWT."""
assert JWTHandler.is_jwt(None) is False
@pytest.mark.asyncio
async def test_both_enabled_opaque_token_uses_oauth2(self):
"""