a2aproject / a2aproject/a2a-js

[Bug]: Authentication fetch wrapper drops Headers entries and corrupts tuple-array headers

オープン
#716 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
613
フォーク
169
平均マージ
1日 6時間
マージ済み PR(30日)
21

説明

## What happened

`createAuthenticatingFetchWithRetry` preserves request headers supplied as a plain object, but loses entries supplied through a `Headers` instance and corrupts a tuple-array `HeadersInit`. This affects both the initial request and the authentication retry.

With `A2A-Version: 1.0` and `Content-Type: application/json`:

- Plain object: both headers are preserved.
- `new Headers(...)`: both headers disappear; only the authentication handler's Authorization header remains.
- `[['A2A-Version', '1.0'], ['Content-Type', 'application/json']]`: the request instead contains headers named `0` and `1`, with comma-joined pair values.

## What I expected

The fetch wrapper should preserve caller headers for all supported `HeadersInit` representations, on both the initial request and retry.

## Steps to reproduce

1. Wrap a mock fetch using `createAuthenticatingFetchWithRetry`, with `headers()` returning an Authorization header and `shouldRetryWithHeaders()` returning a refreshed Authorization header.
2. Have the mock capture `new Request(input, init).headers`, return 401 on its first invocation and 200 on its second.
3. Call the wrapped fetch with `headers: new Headers({ 'A2A-Version': '1.0', 'Content-Type': 'application/json' })`.
4. Observe that both captured requests lack the supplied version and content-type headers.
5. Repeat using a plain object and then a tuple array; observe the comparison above.

## Additional context

This can affect version negotiation, content-type handling, and custom extension headers when composing the authentication helper with other fetch wrappers. The helper is typed as `typeof fetch` and accepts `RequestInit`, whose headers support all these representations.

Normalizing the caller's headers through `Headers` before merging would support those representations while allowing the intended precedence to be preserved.

Fetch standard: https://fetch.spec.whatwg.org/#headers-class

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Look at the `createAuthenticatingFetchWithRetry` function, likely in a file like `src/fetch-wrapper.ts`. Examine how it merges headers from the caller's request init with the authentication headers. The bug is in header normalization; the fix is to convert all header inputs to a `Headers` instance before merging. Write a test that reproduces the issue with the three header representations (object, Headers instance, tuple array) and verifies they are preserved after the fix.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
javascript, typescript
領域
api, authentication
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
活発
明瞭さ
明確に書かれている
初心者へのやさしさ
65/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。