googleapis / googleapis/google-cloud-python

Stripping "Z" from expiry date parsing in Credentials may lead to incorrect expires_at timestamp

Open
#15,192 16 comments 0 reactions 0 assignees View on GitHub
priority: p2 type: cleanup type: feature request
Dominant language
Python
Stars
5.4k
Forks
1.8k
Avg merge
3d 4h
Merged PRs (30d)
122

Description

#### Environment details

- OS: Mac OS 13.2.1
- Python version: 3.10.8
- pip version: 22.2.2
- `google-auth` version: 2.17.0

#### Steps to reproduce

1. Retrieve an initial access token via InstalledAppFlow with no TZ set and system time zone set to UTC-X (e.g. EDT)
2. Observe that expire_at is set beyond 1 hour (it should be returned with 1 hour + abs(time zone difference to UTC))
3. Refresh will not occur as expected and the access token expires

#### Notes

I believe the culprit may be [here](https://github.com/googleapis/google-auth-library-python/blob/main/google/oauth2/credentials.py#L398). The symptom investigations are [here](https://github.com/gilesknap/gphotos-sync/issues/413#issuecomment-1489341338).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.