diff --git a/litellm/proxy/proxy_server.py b/litellm/proxy/proxy_server.py index b713eca2eee..588692d3d4d 100644 --- a/litellm/proxy/proxy_server.py +++ b/litellm/proxy/proxy_server.py @@ -3032,9 +3032,12 @@ class ProxyConfig: if use_pkce and redis_usage_cache is None: verbose_proxy_logger.warning( "GENERIC_CLIENT_USE_PKCE=true but Redis is not configured for LiteLLM caching. " - "PKCE verifiers will not be shared across instances. " + "PKCE verifiers will not be shared across instances — callbacks may land on a " + "different pod than the login request and fail silently. " "Configure Redis via the 'cache' section in your proxy config, " - "or enable sticky sessions for multi-instance deployments." + "or enable sticky sessions for single-instance deployments. " + "Set PKCE_STRICT_CACHE_MISS=true to fail fast with a 401 on cache misses " + "instead of continuing without a code_verifier." ) ### STORE MODEL IN DB ### feature flag for `/model/new` store_model_in_db = general_settings.get("store_model_in_db", False) diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index f19ebaff0ff..f130dfe16bc 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -3195,7 +3195,9 @@ class TestPKCEFunctionality: mock_cache.async_set_cache = AsyncMock() with patch.dict(os.environ, {"GENERIC_CLIENT_USE_PKCE": "true"}): - with patch("litellm.proxy.proxy_server.user_api_key_cache", mock_cache): + with patch("litellm.proxy.proxy_server.redis_usage_cache", None), patch( + "litellm.proxy.proxy_server.user_api_key_cache", mock_cache + ): # Act result = await SSOAuthenticationHandler.get_generic_sso_redirect_response( generic_sso=mock_sso,