Coverage for .venv/lib/python3.13/site-packages/litellm/proxy/management_endpoints/sso/custom_microsoft_sso.py: 43%

19 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-10 12:01 +0000

1""" 

2Custom Microsoft SSO class that allows overriding default Microsoft endpoints. 

3 

4This module provides a subclass of fastapi_sso's MicrosoftSSO that allows 

5custom authorization, token, and userinfo endpoints to be specified via environment 

6variables. 

7 

8Environment Variables: 

9- MICROSOFT_AUTHORIZATION_ENDPOINT: Custom authorization endpoint URL 

10- MICROSOFT_TOKEN_ENDPOINT: Custom token endpoint URL 

11- MICROSOFT_USERINFO_ENDPOINT: Custom userinfo endpoint URL 

12 

13If these are not set, the default Microsoft endpoints are used. 

14""" 

15 

16import os 

17from typing import Final 

18 

19import pydantic 

20from fastapi_sso.sso.base import DiscoveryDocument 

21from fastapi_sso.sso.microsoft import MicrosoftSSO 

22 

23from litellm._logging import verbose_proxy_logger 

24 

25 

26class CustomMicrosoftSSO(MicrosoftSSO): 

27 """ 

28 Microsoft SSO subclass that allows overriding default endpoints via environment variables. 

29 

30 Supports: 

31 - MICROSOFT_AUTHORIZATION_ENDPOINT 

32 - MICROSOFT_TOKEN_ENDPOINT 

33 - MICROSOFT_USERINFO_ENDPOINT 

34 """ 

35 

36 def __init__( 

37 self, 

38 client_id: str, 

39 client_secret: str, 

40 redirect_uri: pydantic.AnyHttpUrl | str | None = None, 

41 allow_insecure_http: bool = False, 

42 scope: list[str] | None = None, 

43 tenant: str | None = None, 

44 ): 

45 super().__init__( 

46 client_id=client_id, 

47 client_secret=client_secret, 

48 redirect_uri=redirect_uri, 

49 allow_insecure_http=allow_insecure_http, 

50 scope=scope, 

51 tenant=tenant, 

52 ) 

53 

54 async def get_discovery_document(self) -> DiscoveryDocument: 

55 """ 

56 Override to support custom endpoints via environment variables. 

57 Falls back to default Microsoft endpoints if not set. 

58 """ 

59 custom_authorization_endpoint: Final = os.getenv("MICROSOFT_AUTHORIZATION_ENDPOINT", None) 

60 custom_token_endpoint: Final = os.getenv("MICROSOFT_TOKEN_ENDPOINT", None) 

61 custom_userinfo_endpoint: Final = os.getenv("MICROSOFT_USERINFO_ENDPOINT", None) 

62 

63 # Use custom endpoints if set, otherwise use defaults 

64 authorization_endpoint: Final = ( 

65 custom_authorization_endpoint or f"https://login.microsoftonline.com/{self.tenant}/oauth2/v2.0/authorize" 

66 ) 

67 token_endpoint = custom_token_endpoint or f"https://login.microsoftonline.com/{self.tenant}/oauth2/v2.0/token" 

68 userinfo_endpoint: Final = custom_userinfo_endpoint or f"https://graph.microsoft.com/{self.version}/me" 

69 

70 if custom_authorization_endpoint or custom_token_endpoint or custom_userinfo_endpoint: 

71 verbose_proxy_logger.debug( 

72 "Using custom Microsoft SSO endpoints - authorization: %s, token: %s, userinfo: %s", 

73 authorization_endpoint, 

74 token_endpoint, 

75 userinfo_endpoint, 

76 ) 

77 

78 return DiscoveryDocument( 

79 authorization_endpoint=authorization_endpoint, 

80 token_endpoint=token_endpoint, 

81 userinfo_endpoint=userinfo_endpoint, 

82 )