googleapis / googleapis/google-cloud-python

google-auth: Avoid auto-retrying 401s on streaming/non-repeatable payloads in sync HTTP transports

Open
#18,238 2 comments 0 reactions 1 assignee Claimed by @agrawalradhika-cell View on GitHub
auth priority: p2 type: bug
Dominant language
Python
Stars
5.4k
Forks
1.8k
Avg merge
3d 4h
Merged PRs (30d)
122

Description

### Determine this is the right repository

- [x] I determined this is the correct repository in which to report this bug.

### Summary of the issue

### Description
In `google.auth.transport.requests.AuthorizedSession` and `google.auth.transport.urllib3.AuthorizedHttp`, receiving a `401 Unauthorized` triggers an automatic credential refresh / mTLS channel reconfiguration, followed by a recursive request retry (`self.request(...)` / `self.urlopen(...)`).

If the request payload (`data` or `body`) is a streaming payload (e.g., a file-like object, generator, or iterator), the initial request consumes the stream. The recursive retry then blindly attempts to send the exact same exhausted stream instance. This results in transmitting a 0-byte body (`Content-Length: 0`) to the server on the retried attempt.

For streaming payloads, the transport should likely not attempt an automatic retry and instead return the `401` response to the caller so they can safely reconstruct the stream and retry on their end. See HLD: go/sdk-mds-bound-token

Note on implementation: If the fix involves short-circuiting the auto-retry for streaming payloads, it is critical that **credential refresh and mTLS channel reconfiguration still execute prior to returning the 401**. If the logic returns early before running `self.credentials.refresh()` and `self.configure_mtls_channel()`, the internal session state remains stale. When the caller reconstructs the stream and issues a manual retry, it will immediately fail again with the exact same expired token or old mTLS certificate.

### Affected Files
- `packages/google-auth/google/auth/transport/requests.py` (`AuthorizedSession.request`)
- `packages/google-auth/google/auth/transport/urllib3.py` (`AuthorizedHttp.urlopen`)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.