Skip to content

OAuth2 token fetch crashes with JSONDecodeError instead of a catchable error on rate-limit responses - #929

Open
juneja-varun wants to merge 2 commits into
authlib:mainfrom
juneja-varun:fix/oauth2-non-json-error-response
Open

juneja-varun wants to merge 2 commits into
authlib:mainfrom
juneja-varun:fix/oauth2-non-json-error-response

Conversation

@juneja-varun

@juneja-varun juneja-varun commented Aug 26, 2026 •

Copy link
Copy Markdown

Fixes #928.

I'm calling a token endpoint behind an API gateway. When the gateway rate-limits me, it sends back a 429 with a plain-text body - completely normal gateway behavior - but fetch_token() crashed with an unhandled json.decoder.JSONDecodeError instead of something catchable.

OAuth2Client.parse_response_token() only calls resp.raise_for_status() for status codes >= 500, so any 4xx with a non-JSON body (rate-limit pages, WAF blocks, plain text) blows up trying to parse it as JSON. Fixed by wrapping the resp.json() call in a try/except and falling back to raise_for_status() on a decode failure, so the caller gets a proper HTTPStatusError instead. Kept the normal OAuth2 flow intact - a 400 with a well-formed JSON error body still raises the expected OAuthError, verified explicitly.

Added a regression test confirming it fails with the exact reported error on unpatched code and passes with the fix.

@juneja-varun

Copy link
Copy Markdown
Author

@lepture the failing tests were a real gap on my end — this repo enforces 100% diff coverage and my fix's re-raise branch (only reachable on a 2xx response with a malformed body) wasn't covered. Added a test for that case and confirmed locally: full suite passes (954 passed, 4 skipped), diff coverage is 100%, and ruff is clean. Could you approve the workflow run again when you get a chance?

@juneja-varun

Copy link
Copy Markdown
Author

Just following up — let me know if there's anything else needed on my end before the workflow can be re-approved.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JSONDecodeError raised instead of a HTTP error

1 participant