apache / apache/iceberg-python

Bug: REST catalog auth cannot be configured via environment variables unless auth JSON strings are decoded

未關閉
#3,422 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
1.1k
分支
581
平均合併
1 天 13 小時
30 天內合併 PR
76

描述

### Apache Iceberg version

None

### Please describe the bug 🐞

### Summary
`RestCatalog._create_session()` expects `auth` to be a dict. When catalog config comes from environment variables, values are strings, so `auth` is received as a string and auth initialization fails.

This blocks env-var-based configuration for pluggable REST auth (`basic`, `oauth2`, `google`, `entra`, `custom`) unless string JSON is explicitly decoded first.

### Minimal repro
```bash
export PYICEBERG_CATALOG__REST__TYPE=rest
export PYICEBERG_CATALOG__REST__URI=http://localhost:8181
export PYICEBERG_CATALOG__REST__AUTH='{"type":"oauth2","oauth2":{"client_id":"id","client_secret":"secret","token_url":"https://auth.example/token"}}'
```

```python
from pyiceberg.catalog import load_catalog
load_catalog("rest")
```

### Actual (without this fix)
Expected: catalog initializes and uses the configured auth manager.

Actual: initialization fails because `auth` is treated as a string and `.get(...)` is called on it.

### Suggested fix
In REST catalog session setup, if `auth` is a string, decode it as JSON before reading `auth.type` and type-specific config.

Add regression tests for both:
- `PYICEBERG_CATALOG____AUTH` (JSON string) initializes auth manager correctly.
- `PYICEBERG_CATALOG____AUTH__...` maps correctly into auth manager configuration.

### Alternative fix (follows current env-var standard)
Support flattened auth properties from environment variables instead of requiring a JSON blob in `...__AUTH`.

Example:

```bash
export PYICEBERG_CATALOG__REST__AUTH__TYPE=oauth2
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_ID=id
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_SECRET=secret
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__TOKEN_URL=https://auth.example/token
```

This aligns with existing flattened env-var configuration behavior and avoids JSON-in-env quoting/escaping issues.

### Verification
Observed with current code path (`Config._from_environment_variables`):

```bash
export PYICEBERG_CATALOG__REST__AUTH__TYPE=oauth2
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_ID=id
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_SECRET=secret
```

Parsed result:

```python
{'catalog': {'rest': {'auth.type': 'oauth2', 'auth.oauth2.client-id': 'id', 'auth.oauth2.client-secret': 'secret'}}}
```

This confirms flattened `AUTH__...` env vars are currently stored as dotted keys, not as a nested `auth` object consumed by `RestCatalog._create_session()`.

### Willingness to contribute

- [ ] I can contribute a fix for this bug independently
- [ ] I would be willing to contribute a fix for this bug with guidance from the Iceberg community
- [ ] I cannot contribute a fix for this bug at this time

貢獻指南

這個儲存庫沒有索引到貢獻指南

研究方向

先閱讀 RestCatalog._create_session() 和 Config._from_environment_variables(),然後重現文件中記載的 REST 驗證環境變數範例。為支援的環境變數表示方式新增回歸測試覆蓋,並驗證 catalog 初始化能夠到達已設定的 auth manager,而不會將 auth 視為不可用的字串或點號鍵映射。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
api, authentication, backend
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。