diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 99ac865b5dd..f07c2face9d 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -2616,9 +2616,9 @@ class SSOAuthenticationHandler: post_kwargs: Dict[str, Any] = { "data": token_data, "headers": { - "Content-Type": "application/x-www-form-urlencoded", - "Accept": "application/json", **additional_headers, + "Content-Type": "application/x-www-form-urlencoded", # must not be overridden + "Accept": "application/json", }, "timeout": 30.0, } @@ -2719,8 +2719,8 @@ class SSOAuthenticationHandler: resp = await client.get( userinfo_endpoint, headers={ - "Authorization": f"Bearer {access_token}", **additional_headers, + "Authorization": f"Bearer {access_token}", # must not be overridden }, timeout=30.0, ) diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index 803c4e0c778..4bac65d6d64 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -4529,6 +4529,8 @@ async def test_pkce_token_exchange_basic_auth(): # Verify Basic Auth is set assert "auth" in kwargs assert isinstance(kwargs["auth"], httpx.BasicAuth) + # Verify code_verifier is in the POST body (essential PKCE field) + assert kwargs.get("data", {}).get("code_verifier") == "verifier_abc" return mock_response with patch("litellm.proxy.management_endpoints.ui_sso.httpx.AsyncClient") as mock_client_cls: