A2A: refuse to serve when no transport credential is configured - #28
Open
nishanthvonteddu wants to merge 1 commit into
Open
nishanthvonteddu wants to merge 1 commit into
nishanthvonteddu wants to merge 1 commit into
Conversation
`A2ADemoServer.rpc` guarded its auth check with
if self.bearer_tokens or self.api_keys:
so a server constructed without either served every caller anonymously.
That is the shape auth.py's own docstring names as the thing to avoid: it
reads like a check and behaves like an open door in exactly the state a
fresh checkout is in. `POST /a2a` is mounted in main.py, and message/send
creates and runs a task, so this is not a missing feature -- it hands any
caller the agent's time and budget.
The existing test proves the gate works once tokens exist; nothing covered
it with none.
Unconfigured now answers 503 and names the variable it wants. Serving
anonymously is still possible through an explicit allow_anonymous, so a
caller that wants an open transport has to say so; the adapter fixture
that relied on the old behaviour now does.
Membership also moves to hmac.compare_digest: `presented in accepted`
compares secrets in non-constant time, where the rest of the repo does not.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The A2A transport check was skipped entirely when no credential happened to be set — so it served every caller anonymously.
What breaks
This is the shape
auth.py's own docstring names as the thing to avoid: "reads like a check and behaves like an open door whenever the variable is unset, which is exactly the state a fresh checkout is in."POST /a2ais mounted inmain.py, andmessage/sendcreates and runs a task. An unconfigured transport is not a missing feature — it hands any caller the agent's time and budget.How to see it break
Start S16 without
S16_A2A_BEARER_TOKENSorS16_A2A_API_KEYS, then post any JSON-RPC call to/a2a. It returns a result, not a 401. I hit this on a running instance.Why it survived
test_jsonrpc_transport_requires_bearer_or_api_keyconstructs the server with tokens. It proves the gate works once armed; nothing covered it disarmed.The fix
auth.py's precedent.allow_anonymous=Truekeeps an open transport available, but only when asked for. The adapter fixture that relied on the old behaviour now says so — which is the point: every open construction becomes visible.hmac.compare_digestreplacespresented in accepted; membership over a set compares secrets in non-constant time, where the rest of the repo does not.Test
test_jsonrpc_transport_refuses_to_serve_with_no_credential_configured— fails before, passes after. Covers both the refusal and the explicit opt-out.