googleapis / googleapis/python-aiplatform

AdkApp: user_id always defaults to 'default-user-id' when called from Google Agentspace

オープン
#6,593 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
api: vertex-ai
主要言語
Python
スター
905
フォーク
465
平均マージ
1日 13時間
マージ済み PR(30日)
44

説明

## Environment

| Component | Value |
|---|---|
| **Package** | `google-cloud-aiplatform` |
| **File** | `vertexai/agent_engines/templates/adk.py` |
| **Python** | 3.12 |
| **Deployment** | Vertex AI Agent Engine via Agentspace |

## Description

When ADK agents are deployed to **Google Agentspace** and users interact through the Agentspace UI, `user_id` is always `"default-user-id"` for all sessions and events. The real user identity (IAM principal/email) is never propagated, making per-user analytics impossible.

### Root cause

In `vertexai/agent_engines/templates/adk.py`, line 97:

```python
_DEFAULT_USER_ID = "default-user-id"
```

The `_StreamRunRequest` constructor (lines 198-200) falls back to this default:

```python
self.user_id: Optional[str] = kwargs.get("user_id") or kwargs.get(
"userId", _DEFAULT_USER_ID
)
```

When Agentspace calls `streaming_agent_run_with_events(request_json)` (line 1166), the incoming JSON does not include a `user_id` or `userId` field. The authenticated user's identity — which Agentspace **does know** (confirmed by `useriamprincipal` in `discoveryengine.googleapis.com` audit logs) — is not passed through to the Agent Engine request payload.

This `"default-user-id"` then propagates through the entire ADK stack:

```
_StreamRunRequest.user_id ("default-user-id")
→ Runner.run_async(user_id=...)
→ Session.user_id
→ InvocationContext.user_id
→ BigQueryAgentAnalyticsPlugin logs it to BQ
```

### Expected behavior

When a user accesses an agent through Agentspace, the `user_id` field in the request should contain the authenticated user's identity (IAM principal or email). The identity is already available in the Agentspace request context — it just needs to be included in the `streaming_agent_run_with_events` request JSON.

### Possible fixes

1. **Agentspace side**: Include the authenticated user's identity in the `user_id` field of the request JSON sent to Agent Engine
2. **Vertex AI SDK side**: In `streaming_agent_run_with_events()` or `_StreamRunRequest`, extract user identity from HTTP request headers or IAM metadata as a fallback, rather than using a hardcoded `"default-user-id"`

### Impact

- All ADK agents deployed to Agentspace are affected
- `BigQueryAgentAnalyticsPlugin` logs `"default-user-id"` for all events, breaking per-user analytics (token usage, session counts, agent adoption)
- Any downstream system relying on `session.user_id` gets the placeholder value

### Related

- Originally reported as google/adk-python#5189 — closed with a pointer to this issue since the root cause is in the Vertex AI SDK, not in ADK

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。