googleapis / googleapis/google-cloud-python
auth: AuthorizedHttp.configure_mtls_channel() drops custom PoolManager settings
- Langage dominant
- Python
- Étoiles
- 5.4k
- Forks
- 1.8k
- Merge moyen
- 3 j 4 h
- PR mergées (30 j)
- 122
Description
In `packages/google-auth/google/auth/transport/urllib3.py`, calling `AuthorizedHttp.configure_mtls_channel()` replaces `self.http` by calling `_make_mutual_tls_http(cert, key)`, which constructs a new `urllib3.PoolManager(ssl_context=ctx)` without copying non-SSL pool settings from the existing `self.http` instance.
When callers initialize `AuthorizedHttp(credentials, http=custom_pool_manager)` with custom retry policies (`retries`), connection pool sizing (`maxsize`, `num_pools`), timeouts (`timeout`), or default headers (`headers`), calling `configure_mtls_channel()` discards all of those custom configurations and emits a `UserWarning` stating that the `http` object provided in the constructor is overwritten.
By contrast, `AuthorizedSession.configure_mtls_channel()` in `packages/google-auth/google/auth/transport/requests.py` preserves custom retry and connection pool sizing (`max_retries`, `pool_connections`, `pool_maxsize`, `pool_block`) from the existing `HTTPAdapter` when mounting `_MutualTlsAdapter`.
### Proposed Fix
Update `_make_mutual_tls_http()` in `packages/google-auth/google/auth/transport/urllib3.py` to accept optional `PoolManager` keyword arguments, and update `AuthorizedHttp.configure_mtls_channel()` to extract non-SSL configuration settings (`retries`, `maxsize`, `block`, `timeout`, `headers`, and `num_pools`) from `self.http` and forward them when constructing the mTLS `PoolManager`.
Update unit tests in `packages/google-auth/tests/transport/test_urllib3.py` to verify that custom retry, pool sizing, timeout, and header configurations on a user-provided `PoolManager` are preserved across `configure_mtls_channel()` calls.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start in packages/google-auth/google/auth/transport/urllib3.py by reading _make_mutual_tls_http() and AuthorizedHttp.configure_mtls_channel(), then compare the preservation behavior in the requests transport. Update the related unit coverage in packages/google-auth/tests/transport/test_urllib3.py so custom retry, pool sizing, timeout, and header settings remain after mTLS configuration, and run those tests.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- python
- Domaine
- authentication
- Type d'issue
- Bug
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Activité
- Active
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 76/100