a2aproject / a2aproject/a2a-python

[Feat]: PushNotificationConfig.authentication is ignored; no Authorization header is sent in push notifications

Đang mở
#585 10 bình luận 0 reaction 1 người được giao Được giao cho @sokoliva Xem trên GitHub
Ngôn ngữ chính
Python
Star
2.1k
Fork
496
Merge trung bình
4 ngày 17 giờ
Pull request đã merge (30 ngày)
12

Mô tả

### Is your feature request related to a problem? Please describe.

The A2A protocol spec states that when a client provides a `PushNotificationConfig` with an authentication scheme (e.g. `"schemes": ["Bearer"]`), the A2A server **must authenticate** when sending push notifications to the client’s webhook.
Example config:

```json
"configuration": {
"pushNotificationConfig": {
"url": "CALLBACK-URL",
"token": "secure-client-token-for-task-aaa",
"authentication": {
"schemes": ["Bearer"]
}
}
}
```

However, the Python implementation (`BasePushNotificationSender`) **completely ignores `authentication`** and sends **no `Authorization` header**.
It only attaches:

```
X-A2A-Notification-Token:
```

This means that webhook endpoints cannot authenticate the caller and cannot follow the security model described in the spec.

This appears to be a **spec compliance gap**: push notification authentication is described by the protocol but not implemented in the Python server.

### Describe the solution you'd like

I would like the Python server to:

* Honor `PushNotificationConfig.authentication`
* Support at least the `"Bearer"` scheme
* Automatically add the appropriate `Authorization` header
* Match the spec examples by sending both:

* `X-A2A-Notification-Token`
* `Authorization: Bearer `

### Describe alternatives you've considered

As a workaround, we currently:

* **Subclass `BasePushNotificationSender`**
* Override `_dispatch_notification`
* Inject our own `Authorization: Bearer ` header

This works, but:

* It duplicates logic that should be part of the framework
* It breaks consistency between Python and other A2A implementations
* It makes spec-compliant webhook security non-standard and harder to maintain

A built-in implementation would make push notification authentication reliable, consistent, and aligned with the A2A spec.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.