googleapis / googleapis/google-cloud-python

auth: get_client_cert_and_key() suppresses default SSL fallback on empty callback

オープン
#18,307 コメント 0 件 リアクション 0 件 担当者 1 名 @agrawalradhika-cell が担当を希望しています GitHub で見る
auth priority: p2 type: bug
主要言語
Python
スター
5.4k
フォーク
1.8k
平均マージ
3日 4時間
マージ済み PR(30日)
122

説明

In `google.auth.aio.transport.mtls.get_client_cert_and_key()`, providing a `client_cert_callback` causes the function to return `(True, cert, key)` unconditionally. When the callback returns `(None, None)` or empty bytes, the function returns `(True, None, None)`.

This violates the documented contract:
> "if the callback is None or doesn't provide certificate and key, the function tries application default SSL credentials"

Because line 176 returns early, execution never falls through to `await get_client_ssl_credentials()`. Downstream callers such as `AsyncAuthorizedSession.configure_mtls_channel()` receive `has_cert = True` and set `self._is_mtls = True`, but passing `(None, None)` into `make_client_cert_ssl_context()` skips `load_cert_chain()` and returns an SSL context without client certificates while the session treats mTLS as active.

The synchronous implementation in `google.auth.transport._mtls_helper.get_client_cert_and_key()` shares this same behavior.

### Proposed Fix
Guard the callback return value to ensure `cert` and `key` are truthy before returning `has_cert = True`:

```python
if client_cert_callback:
result = client_cert_callback()
if inspect.isawaitable(result):
cert, key = await result
else:
cert, key = result
if cert and key:
return True, cert, key

has_cert, cert, key, _ = await get_client_ssl_credentials()
return has_cert, cert, key
```

The corresponding guard should be applied to `google.auth.transport._mtls_helper.get_client_cert_and_key()`. Unit tests in `tests/transport/aio/test_aio_mtls_helper.py` and `tests/transport/test__mtls_helper.py` should assert that callbacks returning `(None, None)` fall back to default SSL credentials when available, or return `(False, None, None)` when no credentials exist.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。