a2aproject / a2aproject/a2a-python

[Bug]: In-memory push store keeps the caller object so later mutations rewrite stored webhooks

Aperta
#1,215 1 commento 0 reazioni 1 assegnatario Rivendicata da @rohityan Vedi su GitHub
component: server status:awaiting response
Lingua principale
Python
Stelle
2.1k
Fork
496
Merge medio
4g 17h
PR unite (30g)
12

Descrizione

### What happened?

`InMemoryPushNotificationConfigStore.set_info` appends the caller proto and `get_info` / `get_info_for_dispatch` return those same objects.

After create/get, changing `url`/`token`/`id` on the request or response proto silently changes the stored webhook. The next `send_notification` POSTs to the mutated URL.

`DatabasePushNotificationConfigStore` already `CopyFrom`s. `InMemoryTaskStore` wraps `CopyingTaskStoreAdapter` for the same reason. The JS SDK had this class of bug and cloned on save.

**Repro**
```python
cfg = TaskPushNotificationConfig(url="http://a.example/cb")
await store.set_info("t1", cfg, ctx)
cfg.url = "http://evil.example/cb"
got = await store.get_info("t1", ctx)
```

Observed: `got[0].url == "http://evil.example/cb"`
Expected: stored copy still `"http://a.example/cb"`

### Relevant log output

n/a.

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.