diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index eecfcaa035b..c95adc73ed1 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -2150,6 +2150,26 @@ class TestCLIKeyRegenerationFlow: result=mock_result, ) + @pytest.mark.asyncio + async def test_auth_callback_raises_on_oauth_error(self): + """Test that auth_callback returns a 401 when the provider redirects with an OAuth error""" + from litellm.proxy.management_endpoints.ui_sso import auth_callback + + mock_request = MagicMock(spec=Request) + mock_request.query_params = { + "error": "access_denied", + "error_description": "User denied consent", + } + + with pytest.raises(HTTPException) as exc_info: + await auth_callback(request=mock_request, state="test-state") + + assert exc_info.value.status_code == 401 + assert ( + exc_info.value.detail + == "OAuth error: access_denied, error_description: User denied consent" + ) + def test_get_redirect_url_does_not_include_existing_key_in_url(self): """Test that redirect URL generation does NOT include existing_key in URL (uses state parameter instead)""" from litellm.proxy.management_endpoints.ui_sso import SSOAuthenticationHandler