googleapis / googleapis/google-cloud-node

google-auth-library: STS credential helpers do not inherit configured transporter

Open
#8,292 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
3.2k
Forks
712
Avg merge
2d 3h
Merged PRs (30d)
99

Description

### Please make sure you have searched for information in the following guides.

- [x] Search the issues already opened: https://github.com/GoogleCloudPlatform/google-cloud-node/issues
- [x] Search StackOverflow: http://stackoverflow.com/questions/tagged/google-cloud-platform+node.js
- [x] Check our Troubleshooting guide: https://github.com/googleapis/google-cloud-node/blob/main/docs/troubleshooting.md
- [x] Check our FAQ: https://github.com/googleapis/google-cloud-node/blob/main/docs/faq.md
- [x] Check our libraries HOW-TO: https://github.com/googleapis/gax-nodejs/blob/main/client-libraries.md
- [x] Check out our authentication guide: https://github.com/googleapis/google-auth-library-nodejs
- [x] Check out handwritten samples for many of our APIs: https://github.com/GoogleCloudPlatform/nodejs-docs-samples
- [x] Check the API's issue tracker: https://cloud.google.com/support/docs/issue-trackers

### Library Name

google-auth-library

### A screenshot that you have tested with "Try this API".

N/A. This is not an API backend behavior issue. It is local client-library transport configuration propagation inside google-auth-library.

### Link to the code that reproduces this issue. A link to a **public** Github Repository or gist with a minimal reproduction.

https://gist.github.com/ashishch432/63841ca0e3a984e2ca66e488ce147776

### A step-by-step description of how to reproduce the issue, based on the linked reproduction.

1. Install google-auth-library and gaxios.
2. Run the reproduction script from the linked gist.
3. Observe that the internally-created STS credentials for BaseExternalAccountClient and DownscopedClient do not use the configured parent transporter.

### A clear and concise description of what the bug is, and what you expected to happen.

AuthClientOptions supports caller-provided transport configuration through `transporter` and `transporterOptions`. BaseExternalAccountClient and DownscopedClient both create internal StsCredentials helpers, but those helpers are constructed without the parent client's configured transporter.

As a result, STS token exchange uses a separate default Gaxios instance instead of the transport configured on the auth client. This can drop custom agents, proxy agents, retry defaults, interceptors, or test transport stubs.

Expected: internally-created StsCredentials helpers should receive `transporter: this.transporter`, matching existing patterns elsewhere in the library.

### A clear and concise description WHY you expect this behavior, i.e., was it a recent change, there is documentation that points to this behavior, etc. **

AuthClient stores caller transport configuration in `this.transporter`. Other internal helpers already receive the parent transporter, for example ExternalAccountAuthorizedUserClient passes `transporter: this.transporter` to its handler, and JwtClient passes `transporter: this.transporter` to GoogleToken. The STS helpers in BaseExternalAccountClient and DownscopedClient appear to have missed the same propagation pattern.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.