Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[Feat]: PushNotificationConfig.authentication is ignored; no Authorization header is sent in push notifications

Chiusa
#585 10 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
45/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Tranquilla
Stack tecnologico
python

Direzione di ricerca

Esamina la classe BasePushNotificationSender per capire come vengono inviate le notifiche push. Il problema è che il campo di autenticazione di PushNotificationConfig viene ignorato. Esamina il parsing della configurazione e il metodo _dispatch_notification. La correzione consiste nel leggere lo schema di autenticazione e aggiungere l’Authorization header appropriato (ad esempio, Bearer) insieme all’X-A2A-Notification-Token esistente. Controlla i test esistenti relativi alle notifiche push per capire il comportamento previsto e aggiungi test per il nuovo header di autenticazione.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Is your feature request related to a problem? Please describe.

The A2A protocol spec states that when a client provides a PushNotificationConfig with an authentication scheme (e.g. "schemes": ["Bearer"]), the A2A server must authenticate when sending push notifications to the client’s webhook.
Example config:

"configuration": {
  "pushNotificationConfig": {
    "url": "CALLBACK-URL",
    "token": "secure-client-token-for-task-aaa",
    "authentication": {
      "schemes": ["Bearer"]
    }
  }
}

However, the Python implementation (BasePushNotificationSender) completely ignores authentication and sends no Authorization header.
It only attaches:

X-A2A-Notification-Token: <token>

This means that webhook endpoints cannot authenticate the caller and cannot follow the security model described in the spec.

This appears to be a spec compliance gap: push notification authentication is described by the protocol but not implemented in the Python server.

Describe the solution you'd like

I would like the Python server to:

  • Honor PushNotificationConfig.authentication

  • Support at least the "Bearer" scheme

  • Automatically add the appropriate Authorization header

  • Match the spec examples by sending both:

    • X-A2A-Notification-Token
    • Authorization: Bearer <token_or_jwt>
Describe alternatives you've considered

As a workaround, we currently:

  • Subclass BasePushNotificationSender
  • Override _dispatch_notification
  • Inject our own Authorization: Bearer <jwt> header

This works, but:

  • It duplicates logic that should be part of the framework
  • It breaks consistency between Python and other A2A implementations
  • It makes spec-compliant webhook security non-standard and harder to maintain

A built-in implementation would make push notification authentication reliable, consistent, and aligned with the A2A spec.

Lingua principale
Python
Stelle
2.2k
Fork
499
Merge medio
3g 15h
PR unite (30g)
28

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di a2aproject/a2a-python

Tutte le issue di a2aproject/a2a-python

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.