From cc1f8c23f2c82fd09fb5b407daffb00c9c06f1d8 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Thu, 5 Mar 2026 13:45:39 -0800 Subject: [PATCH] sanitize PKCE cache log to not expose verifier content --- litellm/proxy/management_endpoints/ui_sso.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 0deea219c8a..7024fad1c59 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -2535,10 +2535,10 @@ class SSOAuthenticationHandler: "This usually means the authorization and callback were handled by different " "instances without a shared cache. " "Ensure Redis is configured and GENERIC_CLIENT_USE_PKCE=true. " - "Cache type: %s. Cached data: %s", + "Cache type: %s. Cache entry present: %s", state, type(user_api_key_cache).__name__, - cached_data, + cached_data is not None, ) return token_params