mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-10 22:41:41 +00:00
made audience optional and updated docs
This commit is contained in:
parent
0ca5af8ae8
commit
66b2b5fab9
2 changed files with 9 additions and 4 deletions
|
|
@ -17,6 +17,7 @@ This is a new feature, and subject to changes based on feedback.
|
|||
### Step 1. Setup Proxy
|
||||
|
||||
- `JWT_PUBLIC_KEY_URL`: This is the public keys endpoint of your OpenID provider. Typically it's `{openid-provider-base-url}/.well-known/openid-configuration/jwks`. For Keycloak it's `{keycloak_base_url}/realms/{your-realm}/protocol/openid-connect/certs`.
|
||||
- `JWT_AUDIENCE`: This is the audience used for decoding the JWT. If not set, the decode step will not verify the audience.
|
||||
|
||||
```bash
|
||||
export JWT_PUBLIC_KEY_URL="" # "https://demo.duendesoftware.com/.well-known/openid-configuration/jwks"
|
||||
|
|
|
|||
|
|
@ -156,6 +156,11 @@ class JWTHandler:
|
|||
return public_key
|
||||
|
||||
async def auth_jwt(self, token: str) -> dict:
|
||||
audience = os.getenv("JWT_AUDIENCE")
|
||||
decode_options = None
|
||||
if audience is None:
|
||||
decode_options = {"verify_aud": False}
|
||||
|
||||
from jwt.algorithms import RSAAlgorithm
|
||||
|
||||
header = jwt.get_unverified_header(token)
|
||||
|
|
@ -185,7 +190,8 @@ class JWTHandler:
|
|||
token,
|
||||
public_key_rsa, # type: ignore
|
||||
algorithms=["RS256"],
|
||||
options={"verify_aud": False},
|
||||
options=decode_options,
|
||||
audience=audience,
|
||||
)
|
||||
return payload
|
||||
|
||||
|
|
@ -195,9 +201,6 @@ class JWTHandler:
|
|||
except Exception as e:
|
||||
raise Exception(f"Validation fails: {str(e)}")
|
||||
elif public_key is not None and isinstance(public_key, str):
|
||||
audience = os.getenv("JWT_AUDIENCE")
|
||||
if audience is None:
|
||||
raise Exception("Missing JWT Audience from environment.")
|
||||
try:
|
||||
cert = x509.load_pem_x509_certificate(public_key.encode(), default_backend())
|
||||
|
||||
|
|
@ -213,6 +216,7 @@ class JWTHandler:
|
|||
key,
|
||||
algorithms=["RS256"],
|
||||
audience=audience,
|
||||
options=decode_options
|
||||
)
|
||||
return payload
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue