mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-08 03:08:45 +00:00
use HTTP 401 for PKCE missing config errors
GENERIC_CLIENT_ID and GENERIC_TOKEN_ENDPOINT missing when PKCE is enabled are auth-flow failures, not server errors. Use 401 instead of 500 to avoid triggering false-positive server error alerts in monitoring systems.
This commit is contained in:
parent
1bc6e2a2a5
commit
9b87bdf176
1 changed files with 2 additions and 2 deletions
|
|
@ -813,14 +813,14 @@ async def get_generic_sso_response(
|
|||
message="GENERIC_CLIENT_ID must be set when PKCE is enabled",
|
||||
type=ProxyErrorTypes.auth_error,
|
||||
param="GENERIC_CLIENT_ID",
|
||||
code=status.HTTP_500_INTERNAL_SERVER_ERROR,
|
||||
code=status.HTTP_401_UNAUTHORIZED,
|
||||
)
|
||||
if not generic_token_endpoint:
|
||||
raise ProxyException(
|
||||
message="GENERIC_TOKEN_ENDPOINT must be set when PKCE is enabled",
|
||||
type=ProxyErrorTypes.auth_error,
|
||||
param="GENERIC_TOKEN_ENDPOINT",
|
||||
code=status.HTTP_500_INTERNAL_SERVER_ERROR,
|
||||
code=status.HTTP_401_UNAUTHORIZED,
|
||||
)
|
||||
# All guards above raise, so authorization_code is a non-empty str here.
|
||||
# Use an explicit type guard rather than assert (assert is a no-op with -O).
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue