googleapis / googleapis/google-cloud-python
auth: AuthorizedHttp.configure_mtls_channel() drops custom PoolManager settings
- 主要語言
- Python
- 星號
- 5.4k
- 分支
- 1.8k
- 平均合併
- 2 天 23 小時
- 30 天內合併 PR
- 123
描述
In `packages/google-auth/google/auth/transport/urllib3.py`, calling `AuthorizedHttp.configure_mtls_channel()` replaces `self.http` by calling `_make_mutual_tls_http(cert, key)`, which constructs a new `urllib3.PoolManager(ssl_context=ctx)` without copying non-SSL pool settings from the existing `self.http` instance.
When callers initialize `AuthorizedHttp(credentials, http=custom_pool_manager)` with custom retry policies (`retries`), connection pool sizing (`maxsize`, `num_pools`), timeouts (`timeout`), or default headers (`headers`), calling `configure_mtls_channel()` discards all of those custom configurations and emits a `UserWarning` stating that the `http` object provided in the constructor is overwritten.
By contrast, `AuthorizedSession.configure_mtls_channel()` in `packages/google-auth/google/auth/transport/requests.py` preserves custom retry and connection pool sizing (`max_retries`, `pool_connections`, `pool_maxsize`, `pool_block`) from the existing `HTTPAdapter` when mounting `_MutualTlsAdapter`.
### Proposed Fix
Update `_make_mutual_tls_http()` in `packages/google-auth/google/auth/transport/urllib3.py` to accept optional `PoolManager` keyword arguments, and update `AuthorizedHttp.configure_mtls_channel()` to extract non-SSL configuration settings (`retries`, `maxsize`, `block`, `timeout`, `headers`, and `num_pools`) from `self.http` and forward them when constructing the mTLS `PoolManager`.
Update unit tests in `packages/google-auth/tests/transport/test_urllib3.py` to verify that custom retry, pool sizing, timeout, and header configurations on a user-provided `PoolManager` are preserved across `configure_mtls_channel()` calls.
貢獻指南
研究方向
Start in packages/google-auth/google/auth/transport/urllib3.py by reading _make_mutual_tls_http() and AuthorizedHttp.configure_mtls_channel(), then compare the preservation behavior in the requests transport. Update the related unit coverage in packages/google-auth/tests/transport/test_urllib3.py so custom retry, pool sizing, timeout, and header settings remain after mTLS configuration, and run those tests.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- authentication
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 活躍
- 描述清晰度
- 描述清楚
- 新手友好度
- 76/100