mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
Generic OIDC providers such as AD FS only attach a Web API's issuance rules (email, first_name, last_name, display_name) when the authorization request names that API through a resource parameter; LiteLLM sent none, so AD FS fell back to urn:microsoft:userinfo and every GENERIC_USER_*_ATTRIBUTE resolved to None. GENERIC_AUTHORIZATION_PARAMS takes a query string (resource=https://litellm.example.com/api) that is parsed with parse_qsl, filtered of the keys the OAuth flow sets itself, and passed to fastapi_sso get_login_redirect(params=...). The setting is exposed through the SSO config resolver, the admin UI SSO form and the generated dashboard schema, with redirect-URL, state, PKCE, parser and form-submit tests. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| litellm-dashboard | ||
| Dockerfile | ||
| nginx.conf | ||