googleapis / googleapis/google-cloud-python

google-auth: Avoid auto-retrying 401s on streaming/non-repeatable payloads in sync HTTP transports

Abierto
#18,238 2 comentarios 0 reacciones 1 asignado Reclamado por @agrawalradhika-cell Ver en GitHub
auth priority: p2 type: bug
Lenguaje dominante
Python
Estrellas
5.4k
Forks
1.8k
Merge medio
3 d 4 h
PR fusionados (30 d)
122

Descripción

### Determine this is the right repository

- [x] I determined this is the correct repository in which to report this bug.

### Summary of the issue

### Description
In `google.auth.transport.requests.AuthorizedSession` and `google.auth.transport.urllib3.AuthorizedHttp`, receiving a `401 Unauthorized` triggers an automatic credential refresh / mTLS channel reconfiguration, followed by a recursive request retry (`self.request(...)` / `self.urlopen(...)`).

If the request payload (`data` or `body`) is a streaming payload (e.g., a file-like object, generator, or iterator), the initial request consumes the stream. The recursive retry then blindly attempts to send the exact same exhausted stream instance. This results in transmitting a 0-byte body (`Content-Length: 0`) to the server on the retried attempt.

For streaming payloads, the transport should likely not attempt an automatic retry and instead return the `401` response to the caller so they can safely reconstruct the stream and retry on their end. See HLD: go/sdk-mds-bound-token

Note on implementation: If the fix involves short-circuiting the auto-retry for streaming payloads, it is critical that **credential refresh and mTLS channel reconfiguration still execute prior to returning the 401**. If the logic returns early before running `self.credentials.refresh()` and `self.configure_mtls_channel()`, the internal session state remains stale. When the caller reconstructs the stream and issues a manual retry, it will immediately fail again with the exact same expired token or old mTLS certificate.

### Affected Files
- `packages/google-auth/google/auth/transport/requests.py` (`AuthorizedSession.request`)
- `packages/google-auth/google/auth/transport/urllib3.py` (`AuthorizedHttp.urlopen`)

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.