From f5412135ce6ee4b857468ae0cbc208f53f3b0f30 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 6 Mar 2026 16:56:50 -0800 Subject: [PATCH] fix misleading comments: code_verifier init and bearer-credential merge docs --- litellm/proxy/management_endpoints/ui_sso.py | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 3c48efddc74..cd88e9105fa 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -782,8 +782,7 @@ async def get_generic_sso_response( key, value = header.split("=") additional_generic_sso_headers_dict[key] = value - # Initialized here so it's visible in the except block for error-hint logic - code_verifier: Optional[str] = None + code_verifier: Optional[str] = None # assigned inside try; initialized for type tracking try: token_exchange_params = await SSOAuthenticationHandler.prepare_token_exchange_parameters( @@ -2905,9 +2904,12 @@ class SSOAuthenticationHandler: # Merge: userinfo takes precedence for identity claims (sub, email, name, …) per # the OpenID Connect spec (userinfo is the authoritative source for identity). - # But bearer credentials (access_token, id_token, refresh_token) must always come - # from the token endpoint, not from userinfo (non-standard providers occasionally - # include these fields in userinfo, which would otherwise shadow the real bearer token). + # Bearer credentials (access_token, id_token, refresh_token) from the token endpoint + # take precedence over same-named fields in userinfo — non-standard providers sometimes + # include token fields in userinfo, which must not shadow the real bearer token. + # If a bearer field is absent from the token response, any userinfo-provided value + # is preserved as a fallback (useful for non-standard providers that omit id_token + # from the token response but include it in userinfo). # # Three-way merge semantics for each bearer-credential field: # 1. token_response has a non-null value → use it (token endpoint is authoritative)