googleapis / googleapis/google-cloud-node
google-auth-library: STS credential helpers do not inherit configured transporter
- Dominant language
- TypeScript
- Stars
- 3.2k
- Forks
- 712
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 99
Description
### Please make sure you have searched for information in the following guides.
- [x] Search the issues already opened: https://github.com/GoogleCloudPlatform/google-cloud-node/issues
- [x] Search StackOverflow: http://stackoverflow.com/questions/tagged/google-cloud-platform+node.js
- [x] Check our Troubleshooting guide: https://github.com/googleapis/google-cloud-node/blob/main/docs/troubleshooting.md
- [x] Check our FAQ: https://github.com/googleapis/google-cloud-node/blob/main/docs/faq.md
- [x] Check our libraries HOW-TO: https://github.com/googleapis/gax-nodejs/blob/main/client-libraries.md
- [x] Check out our authentication guide: https://github.com/googleapis/google-auth-library-nodejs
- [x] Check out handwritten samples for many of our APIs: https://github.com/GoogleCloudPlatform/nodejs-docs-samples
- [x] Check the API's issue tracker: https://cloud.google.com/support/docs/issue-trackers
### Library Name
google-auth-library
### A screenshot that you have tested with "Try this API".
N/A. This is not an API backend behavior issue. It is local client-library transport configuration propagation inside google-auth-library.
### Link to the code that reproduces this issue. A link to a **public** Github Repository or gist with a minimal reproduction.
https://gist.github.com/ashishch432/63841ca0e3a984e2ca66e488ce147776
### A step-by-step description of how to reproduce the issue, based on the linked reproduction.
1. Install google-auth-library and gaxios.
2. Run the reproduction script from the linked gist.
3. Observe that the internally-created STS credentials for BaseExternalAccountClient and DownscopedClient do not use the configured parent transporter.
### A clear and concise description of what the bug is, and what you expected to happen.
AuthClientOptions supports caller-provided transport configuration through `transporter` and `transporterOptions`. BaseExternalAccountClient and DownscopedClient both create internal StsCredentials helpers, but those helpers are constructed without the parent client's configured transporter.
As a result, STS token exchange uses a separate default Gaxios instance instead of the transport configured on the auth client. This can drop custom agents, proxy agents, retry defaults, interceptors, or test transport stubs.
Expected: internally-created StsCredentials helpers should receive `transporter: this.transporter`, matching existing patterns elsewhere in the library.
### A clear and concise description WHY you expect this behavior, i.e., was it a recent change, there is documentation that points to this behavior, etc. **
AuthClient stores caller transport configuration in `this.transporter`. Other internal helpers already receive the parent transporter, for example ExternalAccountAuthorizedUserClient passes `transporter: this.transporter` to its handler, and JwtClient passes `transporter: this.transporter` to GoogleToken. The STS helpers in BaseExternalAccountClient and DownscopedClient appear to have missed the same propagation pattern.
Contributor guide
Assessment
This issue has not been assessed yet.