a2aproject / a2aproject/a2a-python

[Bug]: In-memory push store keeps the caller object so later mutations rewrite stored webhooks

Abierto
#1,215 1 comentario 0 reacciones 1 asignado Reclamado por @rohityan Ver en GitHub
component: server status:awaiting response
Lenguaje dominante
Python
Estrellas
2.1k
Forks
496
Merge medio
4 d 17 h
PR fusionados (30 d)
12

Descripción

### What happened?

`InMemoryPushNotificationConfigStore.set_info` appends the caller proto and `get_info` / `get_info_for_dispatch` return those same objects.

After create/get, changing `url`/`token`/`id` on the request or response proto silently changes the stored webhook. The next `send_notification` POSTs to the mutated URL.

`DatabasePushNotificationConfigStore` already `CopyFrom`s. `InMemoryTaskStore` wraps `CopyingTaskStoreAdapter` for the same reason. The JS SDK had this class of bug and cloned on save.

**Repro**
```python
cfg = TaskPushNotificationConfig(url="http://a.example/cb")
await store.set_info("t1", cfg, ctx)
cfg.url = "http://evil.example/cb"
got = await store.get_info("t1", ctx)
```

Observed: `got[0].url == "http://evil.example/cb"`
Expected: stored copy still `"http://a.example/cb"`

### Relevant log output

n/a.

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.