googleapis / googleapis/google-cloud-python

auth: AuthorizedHttp.configure_mtls_channel() drops custom PoolManager settings

Ouverte
#18,366 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
auth priority: p2 type: bug
Langage dominant
Python
Étoiles
5.4k
Forks
1.8k
Merge moyen
3 j 4 h
PR mergées (30 j)
122

Description

In `packages/google-auth/google/auth/transport/urllib3.py`, calling `AuthorizedHttp.configure_mtls_channel()` replaces `self.http` by calling `_make_mutual_tls_http(cert, key)`, which constructs a new `urllib3.PoolManager(ssl_context=ctx)` without copying non-SSL pool settings from the existing `self.http` instance.

When callers initialize `AuthorizedHttp(credentials, http=custom_pool_manager)` with custom retry policies (`retries`), connection pool sizing (`maxsize`, `num_pools`), timeouts (`timeout`), or default headers (`headers`), calling `configure_mtls_channel()` discards all of those custom configurations and emits a `UserWarning` stating that the `http` object provided in the constructor is overwritten.

By contrast, `AuthorizedSession.configure_mtls_channel()` in `packages/google-auth/google/auth/transport/requests.py` preserves custom retry and connection pool sizing (`max_retries`, `pool_connections`, `pool_maxsize`, `pool_block`) from the existing `HTTPAdapter` when mounting `_MutualTlsAdapter`.

### Proposed Fix

Update `_make_mutual_tls_http()` in `packages/google-auth/google/auth/transport/urllib3.py` to accept optional `PoolManager` keyword arguments, and update `AuthorizedHttp.configure_mtls_channel()` to extract non-SSL configuration settings (`retries`, `maxsize`, `block`, `timeout`, `headers`, and `num_pools`) from `self.http` and forward them when constructing the mTLS `PoolManager`.

Update unit tests in `packages/google-auth/tests/transport/test_urllib3.py` to verify that custom retry, pool sizing, timeout, and header configurations on a user-provided `PoolManager` are preserved across `configure_mtls_channel()` calls.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start in packages/google-auth/google/auth/transport/urllib3.py by reading _make_mutual_tls_http() and AuthorizedHttp.configure_mtls_channel(), then compare the preservation behavior in the requests transport. Update the related unit coverage in packages/google-auth/tests/transport/test_urllib3.py so custom retry, pool sizing, timeout, and header settings remain after mTLS configuration, and run those tests.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
authentication
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
Active
Clarté
Clairement spécifiée
Accessibilité débutants
76/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.