Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

GoogleGcpCredentials: Enforce dictionary type

オープン
#1,207 コメント 0 件 リアクション 0 件 担当者 1 名 GitHub で見る

@vprashrex がすでに取り組んでいます。

2026年9月23日 から。

評価

この issue はまだ評価されていません。

説明

Is your feature request related to a problem?
The current typing of GoogleGcpCredentials.sa_key as JsonValue allows for string inputs, leading to runtime failures when the service account key is treated as a string instead of a dictionary. This results in high diagnostic costs and failed batch assessments.

Describe the solution you'd like
Narrow the annotation of sa_key to enforce a dictionary type:

  • Change sa_key: JsonValue to sa_key: dict[str, JsonValue]
  • This will ensure validation fails at credential-creation time with a clear error, eliminating the need for casting in the code.
  • Note that existing string inputs will need to be re-saved as JSON objects to avoid issues.
Original issue

Problem

GoogleGcpCredentials.sa_key is typed JsonValue:

# backend/app/core/providers.py:76
sa_key: JsonValue = Field(description="Service account key JSON")

Pydantic's JsonValue is the union of all JSON value types — str included. A service account key submitted as an escaped JSON string therefore passes validation and is persisted as-is.

The failure surfaces much later, at provider runtime:

# backend/app/core/batch/google_gcp.py:91
creds = build_gcp_sa_credentials(cast(dict[str, Any], creds_model.sa_key))
# backend/app/core/cloud/storage.py:516
def build_gcp_sa_credentials(sa_key: dict[str, Any]) -> service_account.Credentials:
    return service_account.Credentials.from_service_account_info(sa_key, scopes=list(GCS_SCOPES))

from_service_account_info calls .keys() on the argument, so a stored string raises:

'str' object has no attribute 'keys'

Impact

A batch assessment run fails with status: FAILED and error: "'str' object has no attribute 'keys'", after all items have already been dispatched. Observed with 9/9 items returning assessment: null. The message gives no hint that the stored credential is malformed, so the cost of diagnosis is high.

The cast(dict[str, Any], ...) at the call site also hides this from pyright — the cast asserts a shape the type system never guaranteed.

Proposed fix

Narrow the annotation so the type system enforces what the consumer requires:

sa_key: dict[str, JsonValue] = Field(description="Service account key JSON")

Validation then fails at credential-creation time with a clear Pydantic error instead of at run time. The cast in google_gcp.py becomes unnecessary and should be dropped.

Notes

  • Existing rows holding a string sa_key will not be repaired by the type change; they need to be re-saved (or backfilled) with the key as a JSON object.
  • Masking in mask_credentials (providers.py:260) already assumes non-string secrets for sa_key, so the dict shape is the one the rest of the code expects.
主要言語
Python
スター
18
フォーク
10
平均マージ
2日 23時間
マージ済み PR(30日)
13

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ProjectTech4DevAI/kaapi-backend のほかの issue

ProjectTech4DevAI/kaapi-backend の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。