diff --git a/litellm/proxy/auth/handle_jwt.py b/litellm/proxy/auth/handle_jwt.py index 1b360035bf7..8dac077fe3d 100644 --- a/litellm/proxy/auth/handle_jwt.py +++ b/litellm/proxy/auth/handle_jwt.py @@ -233,7 +233,7 @@ class JWTHandler: # Supported algos: https://pyjwt.readthedocs.io/en/stable/algorithms.html # "Warning: Make sure not to mix symmetric and asymmetric algorithms that interpret # the key in different ways (e.g. HS* and RS*)." - SUPPORTED_JWT_ALGORITHMS = [ # mutable-ok: list kept for backward compatibility + SUPPORTED_JWT_ALGORITHMS = [ *APPROVED_JWT_ALGORITHMS, *LEGACY_JWT_ALGORITHMS, ] @@ -975,9 +975,9 @@ class JWTHandler: allowed: Final = self.allowed_algorithms() usable_keys: Final[JWKKeyValue] = ( - list(jwks_keys_for(keys, allowed)) # mutable-ok: parse_keys consumes a JWKKeyValue list + list(jwks_keys_for(keys, allowed)) if isinstance(keys, list) - else next(iter(jwks_keys_for((keys,), allowed)), {}) # mutable-ok: single-key dict is a JWKKeyValue + else next(iter(jwks_keys_for((keys,), allowed)), {}) ) public_key: Final = self.parse_keys(keys=usable_keys, kid=kid) if public_key is not None: diff --git a/litellm/proxy/guardrails/guardrail_hooks/mcp_jwt_signer/mcp_jwt_signer.py b/litellm/proxy/guardrails/guardrail_hooks/mcp_jwt_signer/mcp_jwt_signer.py index 9256d0fe5f3..75ce60ebacf 100644 --- a/litellm/proxy/guardrails/guardrail_hooks/mcp_jwt_signer/mcp_jwt_signer.py +++ b/litellm/proxy/guardrails/guardrail_hooks/mcp_jwt_signer/mcp_jwt_signer.py @@ -463,9 +463,7 @@ class MCPJWTSigner(CustomGuardrail): from jwt import PyJWKSet try: - jwks_set: Final = PyJWKSet.from_dict( - {"keys": list(approved_keys)} # mutable-ok: PyJWKSet.from_dict takes a dict - ) + jwks_set: Final = PyJWKSet.from_dict({"keys": list(approved_keys)}) except Exception as exc: raise jwt.exceptions.PyJWKSetError(f"Failed to parse JWKS from {jwks_uri!r}: {exc}") from exc