googleapis / googleapis/google-cloud-python

google-auth: Avoid auto-retrying 401s on streaming/non-repeatable payloads in sync HTTP transports

未關閉
#18,238 2 則留言 0 個 reaction 已指派 1 人 在 GitHub 檢視

@agrawalradhika-cell 已經在處理了。

開始於 2026年9月1日。

auth priority: p2 type: bug
主要語言
Python
星號
5.4k
分支
1.8k
平均合併
2 天 23 小時
30 天內合併 PR
123

描述

Determine this is the right repository
  • I determined this is the correct repository in which to report this bug.
Summary of the issue
Description

In google.auth.transport.requests.AuthorizedSession and google.auth.transport.urllib3.AuthorizedHttp, receiving a 401 Unauthorized triggers an automatic credential refresh / mTLS channel reconfiguration, followed by a recursive request retry (self.request(...) / self.urlopen(...)).

If the request payload (data or body) is a streaming payload (e.g., a file-like object, generator, or iterator), the initial request consumes the stream. The recursive retry then blindly attempts to send the exact same exhausted stream instance. This results in transmitting a 0-byte body (Content-Length: 0) to the server on the retried attempt.

For streaming payloads, the transport should likely not attempt an automatic retry and instead return the 401 response to the caller so they can safely reconstruct the stream and retry on their end. See HLD: go/sdk-mds-bound-token

Note on implementation: If the fix involves short-circuiting the auto-retry for streaming payloads, it is critical that credential refresh and mTLS channel reconfiguration still execute prior to returning the 401. If the logic returns early before running self.credentials.refresh() and self.configure_mtls_channel(), the internal session state remains stale. When the caller reconstructs the stream and issues a manual retry, it will immediately fail again with the exact same expired token or old mTLS certificate.

Affected Files
  • packages/google-auth/google/auth/transport/requests.py (AuthorizedSession.request)
  • packages/google-auth/google/auth/transport/urllib3.py (AuthorizedHttp.urlopen)

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。