mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
MCP egress prefixed the configured scheme unconditionally, but callers legitimately supply both a bare token (from a stored credential) and an already-schemed value (passed through from the caller's x-mcp-auth or Authorization header). The second shape produced Authorization: Bearer Bearer <jwt>, which upstream servers reject as a malformed token. It presented intermittently because a resolved stored credential arrives via extra_headers and overwrites the doubled header, so only users without one always failed. strip_auth_scheme drops one leading scheme before the header is rebuilt. It matches the scheme case-insensitively per RFC 7235 and requires a credential behind it, so both a token that merely begins with the scheme text and a scheme with nothing behind it are left intact. MCPAuth.authorization stays verbatim because that auth type means the caller owns the whole header value. For MCPAuth.basic the normalization has to happen in update_auth_value rather than at header-build time: to_basic_auth has already encoded the whole "Basic <credentials>" string by then, so no prefix is left to find. A schemed value whose remainder decodes is already encoded and is reused; one that does not decode is the bare pair with the scheme written in front of it, and is encoded rather than forwarded as an invalid header. The same doubling reached OpenAPI-backed servers through _format_byok_openapi_auth_header. A non-BYOK server short-circuits _resolve_byok_mcp_auth_header, so that formatter also receives the deprecated global x-mcp-auth, which is already a complete header value. |
||
|---|---|---|
| .. | ||
| test_mcp_client.py | ||
| test_tools.py | ||