From fdcdea0d372de3ee536ea3461136b186a4159d02 Mon Sep 17 00:00:00 2001 From: jesus Date: Thu, 17 Sep 2026 02:25:38 +0000 Subject: [PATCH] fix(mcp): clear stale state cookie and mention trusted-proxy config in callback error Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../_experimental/mcp_server/discoverable_endpoints.py | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py index 5bdcfe5be20..5b18b861d64 100644 --- a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py @@ -2256,11 +2256,14 @@ async def callback( description: Final = ( "The OAuth session cookie set when authorization started did not arrive at the callback. " "This usually means the authorize and callback requests used different origins. " - "Ask the gateway operator to set PROXY_BASE_URL to the public URL of this gateway, then retry." + "Ask the gateway operator to set PROXY_BASE_URL to the public URL of this gateway " + "(or configure mcp_trusted_proxy_ranges), then retry." if not cookie_present else "The OAuth session could not be decoded. Start the authorization again." ) - return _render_oauth_error_html("invalid_request", description) + response = _render_oauth_error_html("invalid_request", description) + _clear_oauth_state_cookie(response, request, state) + return response try: original_state = state_data["original_state"]