fix: add pre-flight prisma_client check in connect endpoint, fix FIFO cache comment

- /connect now fails immediately with 503 if prisma_client is None, so
  misconfigured deployments don't waste users through the full provider
  consent flow before failing at /callback.
- Fix "LRU-style" → "FIFO" in _write_byok_cred_cache docstring since
  eviction uses insertion order (first-inserted), not recency.
This commit is contained in:
Ishaan Jaffer 2026-03-07 10:54:21 -08:00
parent eb4f63a655
commit 856215b6cb
2 changed files with 12 additions and 2 deletions

View file

@ -175,6 +175,16 @@ async def openapi_oauth2_connect(
if master_key is None:
raise HTTPException(status_code=500, detail="Master key not configured")
# Fail early if the DB is unavailable: without it the callback cannot store
# the token, so sending the user through the provider consent flow is wasted effort.
from litellm.proxy.proxy_server import prisma_client
if prisma_client is None:
raise HTTPException(
status_code=503,
detail="Database is not configured. Cannot initiate OAuth2 flow.",
)
user_id = user_api_key_dict.user_id or user_api_key_dict.api_key or ""
if not user_id:
raise HTTPException(status_code=400, detail="Cannot determine user identity from token")

View file

@ -105,8 +105,8 @@ def _write_byok_cred_cache(
) -> None:
"""Write a credential value to the cache, evicting the oldest entry if at capacity.
Evicts a single entry (LRU-style) rather than clearing all at once to avoid
a thundering-herd DB spike when the cache fills under load.
Evicts the oldest-inserted entry (FIFO) rather than clearing all at once to
avoid a thundering-herd DB spike when the cache fills under load.
"""
if len(_byok_cred_cache) >= _BYOK_CRED_CACHE_MAX_SIZE:
oldest_key = next(iter(_byok_cred_cache))