From be5a5ccf81d1ec6a11ebed813f3dc242c27c2ba8 Mon Sep 17 00:00:00 2001 From: yucheng Date: Wed, 30 Sep 2026 08:39:05 +0000 Subject: [PATCH] fix(guardrails): return explicitly from every Agent 365 preflight exchange outcome Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../guardrail_hooks/agent_365/agent_365.py | 39 +++++++++---------- 1 file changed, 19 insertions(+), 20 deletions(-) diff --git a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py index 6e5849a92a4..ff06f09114d 100644 --- a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py +++ b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py @@ -497,26 +497,25 @@ class Agent365Guardrail(CustomGuardrail): detail=f"the Entra token endpoint could not be reached ({type(exc).__name__})", fail_open=self.unreachable_fallback == "fail_open", ) - match exchange_result: - case Ok(_): - return SignedIn() - case Error(error): - match error.tag: - case "unauthorized": - return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims) - case "misconfigured": - return Unavailable( - detail=( - f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); " - "check the guardrail's client_id and client_secret" - ), - fail_open=self.unreachable_fallback == "fail_open", - ) - case _: - return Unavailable( - detail=f"the Entra token exchange failed ({error.summary})", - fail_open=self.unreachable_fallback == "fail_open", - ) + if isinstance(exchange_result, Ok): + return SignedIn() + error: Final = exchange_result.error + match error.tag: + case "unauthorized": + return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims) + case "misconfigured": + return Unavailable( + detail=( + f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); " + "check the guardrail's client_id and client_secret" + ), + fail_open=self.unreachable_fallback == "fail_open", + ) + case _: + return Unavailable( + detail=f"the Entra token exchange failed ({error.summary})", + fail_open=self.unreachable_fallback == "fail_open", + ) async def _post_allowing_error_status( self,