Repository navigation
fix(auth): retry transient STS error responses #18564
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -35,7 +35,8 @@ | |||||||||||||||||||||
| import json | ||||||||||||||||||||||
| import urllib | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| from google.oauth2 import utils | ||||||||||||||||||||||
| from google.auth import _exponential_backoff | ||||||||||||||||||||||
| from google.oauth2 import _client, utils | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| _URLENCODED_HEADERS = {"Content-Type": "application/x-www-form-urlencoded"} | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
|
|
@@ -71,30 +72,33 @@ def _make_request(self, request, headers, request_body, url=None): | |||||||||||||||||||||
| # Use default token exchange endpoint if no url is provided. | ||||||||||||||||||||||
| url = url or self._token_exchange_endpoint | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| # Execute request. | ||||||||||||||||||||||
| response = request( | ||||||||||||||||||||||
| url=url, | ||||||||||||||||||||||
| method="POST", | ||||||||||||||||||||||
| headers=request_headers, | ||||||||||||||||||||||
| body=urllib.parse.urlencode(request_body).encode("utf-8"), | ||||||||||||||||||||||
| ) | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| response_body = ( | ||||||||||||||||||||||
| response.data.decode("utf-8") | ||||||||||||||||||||||
| if hasattr(response.data, "decode") | ||||||||||||||||||||||
| else response.data | ||||||||||||||||||||||
| ) | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| # If non-200 response received, translate to OAuthError exception. | ||||||||||||||||||||||
| if response.status != http_client.OK: | ||||||||||||||||||||||
| utils.handle_error_response(response_body) | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| # A successful token revocation returns an empty response body. | ||||||||||||||||||||||
| if not response_body: | ||||||||||||||||||||||
| return {} | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| # Other successful responses should be valid JSON. | ||||||||||||||||||||||
| return json.loads(response_body) | ||||||||||||||||||||||
| encoded_body = urllib.parse.urlencode(request_body).encode("utf-8") | ||||||||||||||||||||||
| for _ in _exponential_backoff.ExponentialBackoff(): | ||||||||||||||||||||||
| response = request( | ||||||||||||||||||||||
| url=url, | ||||||||||||||||||||||
| method="POST", | ||||||||||||||||||||||
| headers=request_headers, | ||||||||||||||||||||||
| body=encoded_body, | ||||||||||||||||||||||
| ) | ||||||||||||||||||||||
| response_body = ( | ||||||||||||||||||||||
| response.data.decode("utf-8") | ||||||||||||||||||||||
| if hasattr(response.data, "decode") | ||||||||||||||||||||||
| else (response.data or "") | ||||||||||||||||||||||
| ) | ||||||||||||||||||||||
|
Comment on lines
+83
to
+87
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If
Suggested change
|
||||||||||||||||||||||
|
|
||||||||||||||||||||||
| if response.status == http_client.OK: | ||||||||||||||||||||||
| # A successful token revocation returns an empty body. | ||||||||||||||||||||||
| return json.loads(response_body) if response_body else {} | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| try: | ||||||||||||||||||||||
| response_data = json.loads(response_body) | ||||||||||||||||||||||
| except ValueError: | ||||||||||||||||||||||
| response_data = response_body | ||||||||||||||||||||||
| retryable = _client._can_retry(response.status, response_data) | ||||||||||||||||||||||
| if not retryable: | ||||||||||||||||||||||
| break | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| utils.handle_error_response(response_body, retryable=retryable) | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
| def exchange_token( | ||||||||||||||||||||||
| self, | ||||||||||||||||||||||
|
|
||||||||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
To prevent potential
UnboundLocalErrorexceptions if the_exponential_backoff.ExponentialBackoff()generator is empty or mocked to return no elements, initializeresponse_bodyandretryablebefore entering the loop.