diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 1d00e721fda..99ac865b5dd 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -822,7 +822,7 @@ async def get_generic_sso_response( # Strip bearer credentials from received_response after conversion. # received_response may appear in restricted-group error messages — # do not expose tokens to callers. - if received_response: + if received_response is not None: received_response = { k: v for k, v in received_response.items() if k not in _OAUTH_TOKEN_FIELDS } @@ -2687,6 +2687,8 @@ class SSOAuthenticationHandler: bool(token_response.get("id_token")), ) + # token_response is set inside the async with block above and remains accessible here; + # Python's scoping rules guarantee it is defined if no exception was raised. userinfo = await SSOAuthenticationHandler._get_pkce_userinfo( access_token=token_response["access_token"], id_token=token_response.get("id_token"), diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index fa591b89660..803c4e0c778 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -4553,6 +4553,10 @@ async def test_pkce_token_exchange_basic_auth(): assert result["access_token"] == "tok_abc" assert result["email"] == "user@example.com" + # Verify userinfo GET used the correct Bearer token header + get_call = mock_client.get.call_args + assert get_call is not None + assert get_call.kwargs["headers"]["Authorization"] == "Bearer tok_abc" @pytest.mark.asyncio