mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
The multi-server list path already relays an upstream 401 from a client-forwarded server (true_passthrough / oauth_delegate) as an MCPUpstreamAuthError so the caller re-runs its own upstream OAuth. The single-server REST call path did not: an upstream 401 was masked as a graceful isError result, so an MCP client holding an expired upstream token never learned it had to re-authenticate Relay the upstream 401 on the call path too. For these modes the manager calls the client with raise_on_error=True, extracts the WWW-Authenticate through the existing upstream-auth exception walk, and raises MCPUpstreamAuthError; the REST endpoint turns it into a real 401 + WWW-Authenticate. Only 401 is treated as a re-auth signal (a 403 is a genuine authorization failure that re-auth will not fix, so it stays a masked isError with a visible warning), matching the list path and MCPUpstreamAuthError's contract. The legacy oauth2 + delegate_auth_to_upstream mode is deliberately left off the call-path relay since it is being removed To keep this expected caller-must-reauth signal from tripping error-rate alerts, the client layer logs at debug when the caller opted into raise_on_error and therefore owns the exception (both call_tool/list_tools and the run_with_session helper they share, so an expected re-auth emits no warning per call either), the manager's non-auth branch logs the exception type only (never str(e), which for an httpx error embeds the upstream URL a credential can hide in), and the streamable and REST handlers log the relayed 401 at info rather than as an error with a traceback Tests cover the manager raising on a client-forwarded 401 while keeping a 403/503 as a masked isError, the client-layer debug-vs-error logging split, the streamable handler's informational isError, and the REST endpoint relaying both the direct and virtual mcp_tool_call branches as a real 401 + WWW-Authenticate; each was mutation-checked to fail when the corresponding behavior is broken |
||
|---|---|---|
| .. | ||
| test_mcp_client.py | ||
| test_tools.py | ||