GoogleGcpCredentials: Enforce dictionary type
@vprashrex がすでに取り組んでいます。
2026年9月23日 から。
評価
この issue はまだ評価されていません。
説明
Is your feature request related to a problem?
The current typing of GoogleGcpCredentials.sa_key as JsonValue allows for string inputs, leading to runtime failures when the service account key is treated as a string instead of a dictionary. This results in high diagnostic costs and failed batch assessments.
Describe the solution you'd like
Narrow the annotation of sa_key to enforce a dictionary type:
- Change
sa_key: JsonValuetosa_key: dict[str, JsonValue] - This will ensure validation fails at credential-creation time with a clear error, eliminating the need for casting in the code.
- Note that existing string inputs will need to be re-saved as JSON objects to avoid issues.
Original issue
Problem
GoogleGcpCredentials.sa_key is typed JsonValue:
# backend/app/core/providers.py:76
sa_key: JsonValue = Field(description="Service account key JSON")
Pydantic's JsonValue is the union of all JSON value types — str included. A service account key submitted as an escaped JSON string therefore passes validation and is persisted as-is.
The failure surfaces much later, at provider runtime:
# backend/app/core/batch/google_gcp.py:91
creds = build_gcp_sa_credentials(cast(dict[str, Any], creds_model.sa_key))
# backend/app/core/cloud/storage.py:516
def build_gcp_sa_credentials(sa_key: dict[str, Any]) -> service_account.Credentials:
return service_account.Credentials.from_service_account_info(sa_key, scopes=list(GCS_SCOPES))
from_service_account_info calls .keys() on the argument, so a stored string raises:
'str' object has no attribute 'keys'
Impact
A batch assessment run fails with status: FAILED and error: "'str' object has no attribute 'keys'", after all items have already been dispatched. Observed with 9/9 items returning assessment: null. The message gives no hint that the stored credential is malformed, so the cost of diagnosis is high.
The cast(dict[str, Any], ...) at the call site also hides this from pyright — the cast asserts a shape the type system never guaranteed.
Proposed fix
Narrow the annotation so the type system enforces what the consumer requires:
sa_key: dict[str, JsonValue] = Field(description="Service account key JSON")
Validation then fails at credential-creation time with a clear Pydantic error instead of at run time. The cast in google_gcp.py becomes unnecessary and should be dropped.
Notes
- Existing rows holding a string
sa_keywill not be repaired by the type change; they need to be re-saved (or backfilled) with the key as a JSON object. - Masking in
mask_credentials(providers.py:260) already assumes non-string secrets forsa_key, so the dict shape is the one the rest of the code expects.
- 主要言語
- Python
- スター
- 18
- フォーク
- 10
- 平均マージ
- 2日 23時間
- マージ済み PR(30日)
- 13
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ProjectTech4DevAI/kaapi-backend のほかの issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
ProjectTech4DevAI/kaapi-backend#269 · コメント 1 件 ·
-
ProjectTech4DevAI/kaapi-backend#1206 · 担当者 1 名 ·
-
ProjectTech4DevAI/kaapi-backend#1184 · 担当者 1 名 ·
-
ProjectTech4DevAI/kaapi-backend#1183 · 担当者 1 名 ·
ProjectTech4DevAI/kaapi-backend の issue をすべて見る
似ている issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
xinnan-tech/xiaozhi-fde-talk#263 ·
-
rules
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
huggingface/Repo2RLEnv#163 · コメント 1 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
huggingface/sentence-transformers#4074 ·
-
comp/dashboard invalid P3
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
NousResearch/hermes-agent#121143 ·