litellm/ui
yassin 95f78a0072 feat(sso): add GENERIC_AUTHORIZATION_PARAMS for extra authorize query params
Generic OIDC providers such as AD FS only attach a Web API's issuance rules (email, first_name, last_name, display_name) when the authorization request names that API through a resource parameter; LiteLLM sent none, so AD FS fell back to urn:microsoft:userinfo and every GENERIC_USER_*_ATTRIBUTE resolved to None. GENERIC_AUTHORIZATION_PARAMS takes a query string (resource=https://litellm.example.com/api) that is parsed with parse_qsl, filtered of the keys the OAuth flow sets itself, and passed to fastapi_sso get_login_redirect(params=...). The setting is exposed through the SSO config resolver, the admin UI SSO form and the generated dashboard schema, with redirect-URL, state, PKCE, parser and form-submit tests.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-10-02 01:42:43 +00:00
..
litellm-dashboard feat(sso): add GENERIC_AUTHORIZATION_PARAMS for extra authorize query params 2026-10-02 01:42:43 +00:00
Dockerfile fix(docker): bump nginx runtime to 1.31.5-alpine3.24 and pin digest to resolve critical CVEs (#39561) 2026-09-03 08:46:07 -07:00
nginx.conf fix(ui): boot the UI image as an arbitrary uid by anchoring nginx writes under /tmp (#37982) 2026-08-24 11:57:36 -07:00