[Feat]: PushNotificationConfig.authentication is ignored; no Authorization header is sent in push notifications
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- python
- Ambito
- api, authentication, backend, security
Direzione di ricerca
Esamina la classe BasePushNotificationSender per capire come vengono inviate le notifiche push. Il problema è che il campo di autenticazione di PushNotificationConfig viene ignorato. Esamina il parsing della configurazione e il metodo _dispatch_notification. La correzione consiste nel leggere lo schema di autenticazione e aggiungere l’Authorization header appropriato (ad esempio, Bearer) insieme all’X-A2A-Notification-Token esistente. Controlla i test esistenti relativi alle notifiche push per capire il comportamento previsto e aggiungi test per il nuovo header di autenticazione.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Is your feature request related to a problem? Please describe.
The A2A protocol spec states that when a client provides a PushNotificationConfig with an authentication scheme (e.g. "schemes": ["Bearer"]), the A2A server must authenticate when sending push notifications to the client’s webhook.
Example config:
"configuration": {
"pushNotificationConfig": {
"url": "CALLBACK-URL",
"token": "secure-client-token-for-task-aaa",
"authentication": {
"schemes": ["Bearer"]
}
}
}
However, the Python implementation (BasePushNotificationSender) completely ignores authentication and sends no Authorization header.
It only attaches:
X-A2A-Notification-Token: <token>
This means that webhook endpoints cannot authenticate the caller and cannot follow the security model described in the spec.
This appears to be a spec compliance gap: push notification authentication is described by the protocol but not implemented in the Python server.
Describe the solution you'd like
I would like the Python server to:
-
Honor
PushNotificationConfig.authentication -
Support at least the
"Bearer"scheme -
Automatically add the appropriate
Authorizationheader -
Match the spec examples by sending both:
X-A2A-Notification-TokenAuthorization: Bearer <token_or_jwt>
Describe alternatives you've considered
As a workaround, we currently:
- Subclass
BasePushNotificationSender - Override
_dispatch_notification - Inject our own
Authorization: Bearer <jwt>header
This works, but:
- It duplicates logic that should be part of the framework
- It breaks consistency between Python and other A2A implementations
- It makes spec-compliant webhook security non-standard and harder to maintain
A built-in implementation would make push notification authentication reliable, consistent, and aligned with the A2A spec.
- Lingua principale
- Python
- Stelle
- 2.2k
- Fork
- 499
- Merge medio
- 3g 15h
- PR unite (30g)
- 28
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di a2aproject/a2a-python
-
Create push notification config returns no id on database-backed storesForse già presa @ConnorMoss02 l’ha presa 4 giorni fa. Apertacomponent: server
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
a2aproject/a2a-python#1237 · 2 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
-
maintainers-only
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
a2aproject/a2a-python#805 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
[Feat]: Change Httpx to Httpx2Forse già presa @rohityan l’ha presa 1 giorno fa. Apertacomponent: client status: needs review
a2aproject/a2a-python#1288 · 2 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
-
[Bug]: Streaming follow-up on an existing task does not begin with a Task; enqueuing the current task drops the follow-up message from historyForse già presa @rohityan l’ha presa 2 giorni fa. Apertacomponent: server status:awaiting response
a2aproject/a2a-python#1285 · 1 commento · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
-
component: core
a2aproject/a2a-python#1278 · 9 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di a2aproject/a2a-python
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
raullenchai/Rapid-MLX#4042 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
LearningCircuit/local-deep-research#7067 ·
I maintainer di solito rispondono entro 1 giorno
-
#bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
apache/superset#44923 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
lawndoc/stack-back#123 ·