a2aproject / a2aproject/a2a-python

[Bug]: In-memory push store keeps the caller object so later mutations rewrite stored webhooks

オープン
#1,215 コメント 1 件 リアクション 0 件 担当者 1 名 @rohityan が担当を希望しています GitHub で見る
component: server status:awaiting response
主要言語
Python
スター
2.1k
フォーク
496
平均マージ
4日 17時間
マージ済み PR(30日)
12

説明

### What happened?

`InMemoryPushNotificationConfigStore.set_info` appends the caller proto and `get_info` / `get_info_for_dispatch` return those same objects.

After create/get, changing `url`/`token`/`id` on the request or response proto silently changes the stored webhook. The next `send_notification` POSTs to the mutated URL.

`DatabasePushNotificationConfigStore` already `CopyFrom`s. `InMemoryTaskStore` wraps `CopyingTaskStoreAdapter` for the same reason. The JS SDK had this class of bug and cloned on save.

**Repro**
```python
cfg = TaskPushNotificationConfig(url="http://a.example/cb")
await store.set_info("t1", cfg, ctx)
cfg.url = "http://evil.example/cb"
got = await store.get_info("t1", ctx)
```

Observed: `got[0].url == "http://evil.example/cb"`
Expected: stored copy still `"http://a.example/cb"`

### Relevant log output

n/a.

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。