mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
* feat(mcp): advertise the SDK's latest spec revision and validate the RFC 9207 iss MCPSpecVersion stopped at 2025-06-18 while the pinned SDK negotiates 2025-11-25, and the version LiteLLM puts on its own outbound initialize was a hardcoded historical member. Add the missing revision, name the highest revision we speak once, and pin it to the SDK's LATEST_PROTOCOL_VERSION with a test so the two cannot drift apart silently. /authorize now seals the issuer it sent the user to into the OAuth state, and /callback holds the authorization response's RFC 9207 iss against it, refusing to forward a code that came back from an authorization server we never sent the user to. An absent iss, an unanchored server row and a state minted before the seal all keep their current behavior. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(mcp): keep params, query and fragment significant in issuer comparison The shared canonicalizer drops all three, so two issuers differing only outside the path compared equal and a response from another tenant's authorization server would have continued through the flow. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(mcp): refresh generated API snapshots Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * test(mcp): cover OAuth client isolation and lint checks * fix(mcp): preserve registered clients in the existing save payload * test(mcp): cover optional OAuth registration metadata * fix(mcp): preserve compatible OAuth registrations across edits * fix(mcp): retain OAuth state through pending authorization * fix(mcp): guard pending OAuth at form submission * fix(mcp): discard canceled OAuth edit snapshots * test(mcp): preserve complete OAuth registration assertions * refactor(mcp): construct OAuth credential updates without mutation * fix(mcp): simplify issuer binding and reject unverifiable callbacks * fix(mcp): preserve replacement clients and pending redirect bindings * fix(mcp): retain clients with replacement authentication methods * fix(mcp): preserve cached clients and pin manual OAuth issuers --------- Co-authored-by: yucheng <yucheng@berri.ai> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: yassin <yassin@berri.ai> Co-authored-by: Joshua Valluru <326636767+joshua-berri@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| a2a | ||
| access_control | ||
| batches | ||
| claude_code | ||
| coverage_registry | ||
| gateway | ||
| guardrails | ||
| llm_translation | ||
| load | ||
| logging | ||
| management | ||
| mcp | ||
| migrations | ||
| other | ||
| quota_management | ||
| router | ||
| secret_manager | ||
| ui | ||
| AGENTS.md | ||
| conftest.py | ||
| CONTRIBUTING.md | ||
| e2e_config.py | ||
| e2e_db.py | ||
| e2e_http.py | ||
| e2e_metadata.py | ||
| fixture_bundle.py | ||
| fixture_canonical.py | ||
| fixture_mode.py | ||
| fixture_profile.py | ||
| idp.py | ||
| idp_realm.json | ||
| junit_properties.py | ||
| lifecycle.py | ||
| memory_readings.py | ||
| models.py | ||
| otel_client.py | ||
| PROVIDER_CACHE.md | ||
| provider_cache.py | ||
| provider_cache_redis.py | ||
| provider_cache_routing.py | ||
| provider_edge.py | ||
| provider_edge_bedrock.py | ||
| proxy_client.py | ||
| pytest.ini | ||
| stack_lock.py | ||
| test_e2e_http.py | ||
| test_fixture_bundle.py | ||
| test_fixture_canonical.py | ||
| test_fixture_mode.py | ||
| test_idp.py | ||
| test_junit_properties.py | ||
| test_provider_edge.py | ||
| test_proxy_client.py | ||
| test_stack_lock.py | ||
| transport.py | ||