googleapis / googleapis/python-aiplatform
AdkApp: user_id always defaults to 'default-user-id' when called from Google Agentspace
- 主要语言
- Python
- 星标
- 905
- 派生
- 465
- 平均合并
- 1 天 13 小时
- 30 天内合并 PR
- 44
描述
## Environment
| Component | Value |
|---|---|
| **Package** | `google-cloud-aiplatform` |
| **File** | `vertexai/agent_engines/templates/adk.py` |
| **Python** | 3.12 |
| **Deployment** | Vertex AI Agent Engine via Agentspace |
## Description
When ADK agents are deployed to **Google Agentspace** and users interact through the Agentspace UI, `user_id` is always `"default-user-id"` for all sessions and events. The real user identity (IAM principal/email) is never propagated, making per-user analytics impossible.
### Root cause
In `vertexai/agent_engines/templates/adk.py`, line 97:
```python
_DEFAULT_USER_ID = "default-user-id"
```
The `_StreamRunRequest` constructor (lines 198-200) falls back to this default:
```python
self.user_id: Optional[str] = kwargs.get("user_id") or kwargs.get(
"userId", _DEFAULT_USER_ID
)
```
When Agentspace calls `streaming_agent_run_with_events(request_json)` (line 1166), the incoming JSON does not include a `user_id` or `userId` field. The authenticated user's identity — which Agentspace **does know** (confirmed by `useriamprincipal` in `discoveryengine.googleapis.com` audit logs) — is not passed through to the Agent Engine request payload.
This `"default-user-id"` then propagates through the entire ADK stack:
```
_StreamRunRequest.user_id ("default-user-id")
→ Runner.run_async(user_id=...)
→ Session.user_id
→ InvocationContext.user_id
→ BigQueryAgentAnalyticsPlugin logs it to BQ
```
### Expected behavior
When a user accesses an agent through Agentspace, the `user_id` field in the request should contain the authenticated user's identity (IAM principal or email). The identity is already available in the Agentspace request context — it just needs to be included in the `streaming_agent_run_with_events` request JSON.
### Possible fixes
1. **Agentspace side**: Include the authenticated user's identity in the `user_id` field of the request JSON sent to Agent Engine
2. **Vertex AI SDK side**: In `streaming_agent_run_with_events()` or `_StreamRunRequest`, extract user identity from HTTP request headers or IAM metadata as a fallback, rather than using a hardcoded `"default-user-id"`
### Impact
- All ADK agents deployed to Agentspace are affected
- `BigQueryAgentAnalyticsPlugin` logs `"default-user-id"` for all events, breaking per-user analytics (token usage, session counts, agent adoption)
- Any downstream system relying on `session.user_id` gets the placeholder value
### Related
- Originally reported as google/adk-python#5189 — closed with a pointer to this issue since the root cause is in the Vertex AI SDK, not in ADK
贡献指南
调研方向
Start in vertexai/agent_engines/templates/adk.py, reading _StreamRunRequest and streaming_agent_run_with_events() around the referenced lines. Trace how the incoming request JSON and authenticated request context are represented before the default user ID is assigned. Done means the Agentspace user identity reaches the ADK session and analytics path, with regression coverage for requests that omit user_id.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- google-cloud, python
- 领域
- api, authentication, cloud
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 45/100