googleapis / googleapis/google-cloud-python

google-auth: Local developer mTLS environment leaks into unit tests, causing mock failures

Aberta Para iniciantes
#17,283 0 comentários 0 reações 0 responsáveis Ver no GitHub
type: bug
Linguagem predominante
Python
Estrelas
5.4k
Forks
1.8k
Merge médio
2d 23h
PRs com merge (30d)
123

Descrição

### Determine this is the right repository

- [x] I determined this is the correct repository in which to report this bug.

### Summary of the issue

When running unit tests locally on developer machines that have context-aware access or enterprise mTLS configured (such as Google-managed corporate MacBooks), several tests fail unexpectedly.

This happens because the test suite's global configuration (`tests/conftest.py`) does not sanitize the environment. Global environment variables (like `GOOGLE_API_CERTIFICATE_CONFIG` or `GOOGLE_API_USE_CLIENT_CERTIFICATE`) and default configuration files (like `~/.config/gcloud/certificate_config.json`) leak directly into the `pytest` session.

Any test that does not explicitly mock `_mtls_helper.check_use_client_cert()` or clear these environment variables will transition to using mTLS hostnames (e.g. expecting `iamcredentials.googleapis.com` but getting `iamcredentials.mtls.googleapis.com`). Since the mock networks in the tests are configured with standard endpoints, the requests fail to match the mock setups, causing transport exceptions and test failures.

### Proposed fix
Introduce a function-scoped, autouse fixture in `tests/conftest.py` to establish a clean, hermetic environment for every unit test. Using pytest's standard `monkeypatch` fixture ensures all local environmental variables and mocks are automatically cleaned up and restored back to the developer's original workstation state after each test executes. This can be accomplished by something like:

```python
# tests/conftest.py
@pytest.fixture(autouse=True)
def clean_mtls_environment(monkeypatch):
from google.auth.transport import _mtls_helper

# Pop all mTLS-related environment variables
for var in [
"GOOGLE_API_USE_CLIENT_CERTIFICATE",
"GOOGLE_API_CERTIFICATE_CONFIG",
"CLOUDSDK_CONTEXT_AWARE_USE_CLIENT_CERTIFICATE",
"CLOUDSDK_CONTEXT_AWARE_CERTIFICATE_CONFIG_FILE_PATH",
]:
monkeypatch.delenv(var, raising=False)

# Mock check_use_client_cert to return False by default
monkeypatch.setattr(_mtls_helper, "check_use_client_cert", lambda: False)
```

This way tests specifically designed to verify mTLS behaviors can easily override the global mock locally by re-patching the method in their own bodies (which runs after the global autouse setup):
```python
def test_mtls_behavior(monkeypatch):
from google.auth.transport import _mtls_helper
monkeypatch.setattr(_mtls_helper, "check_use_client_cert", lambda: True)
# Test runs with mTLS enabled cleanly
```

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece em tests/conftest.py e revise os fixtures existentes do pytest e os testes relacionados a mTLS. Execute a suíte de testes unitários com variáveis de ambiente locais de mTLS ou com uma configuração de certificados presente e, em seguida, verifique se os testes comuns usam endpoints padrão, enquanto os testes que habilitam explicitamente o mTLS continuam passando. O trabalho estará concluído quando o ambiente estiver isolado por teste e for restaurado depois.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
python
Domínio
testing-qa
Tipo de issue
Bug
Dificuldade
2/5
Tempo estimado
1-3 horas
Status de atividade
Pouca atividade
Clareza
Claramente especificada
Facilidade para iniciantes
76/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.