googleapis / googleapis/google-cloud-python
auth: AuthorizedHttp.configure_mtls_channel() drops custom PoolManager settings
- Ngôn ngữ chính
- Python
- Star
- 5.4k
- Fork
- 1.8k
- Merge trung bình
- 3 ngày 4 giờ
- Pull request đã merge (30 ngày)
- 122
Mô tả
In `packages/google-auth/google/auth/transport/urllib3.py`, calling `AuthorizedHttp.configure_mtls_channel()` replaces `self.http` by calling `_make_mutual_tls_http(cert, key)`, which constructs a new `urllib3.PoolManager(ssl_context=ctx)` without copying non-SSL pool settings from the existing `self.http` instance.
When callers initialize `AuthorizedHttp(credentials, http=custom_pool_manager)` with custom retry policies (`retries`), connection pool sizing (`maxsize`, `num_pools`), timeouts (`timeout`), or default headers (`headers`), calling `configure_mtls_channel()` discards all of those custom configurations and emits a `UserWarning` stating that the `http` object provided in the constructor is overwritten.
By contrast, `AuthorizedSession.configure_mtls_channel()` in `packages/google-auth/google/auth/transport/requests.py` preserves custom retry and connection pool sizing (`max_retries`, `pool_connections`, `pool_maxsize`, `pool_block`) from the existing `HTTPAdapter` when mounting `_MutualTlsAdapter`.
### Proposed Fix
Update `_make_mutual_tls_http()` in `packages/google-auth/google/auth/transport/urllib3.py` to accept optional `PoolManager` keyword arguments, and update `AuthorizedHttp.configure_mtls_channel()` to extract non-SSL configuration settings (`retries`, `maxsize`, `block`, `timeout`, `headers`, and `num_pools`) from `self.http` and forward them when constructing the mTLS `PoolManager`.
Update unit tests in `packages/google-auth/tests/transport/test_urllib3.py` to verify that custom retry, pool sizing, timeout, and header configurations on a user-provided `PoolManager` are preserved across `configure_mtls_channel()` calls.
Hướng dẫn đóng góp
Hướng nghiên cứu
Start in packages/google-auth/google/auth/transport/urllib3.py by reading _make_mutual_tls_http() and AuthorizedHttp.configure_mtls_channel(), then compare the preservation behavior in the requests transport. Update the related unit coverage in packages/google-auth/tests/transport/test_urllib3.py so custom retry, pool sizing, timeout, and header settings remain after mTLS configuration, and run those tests.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- authentication
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức phù hợp với người mới
- 76/100