Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

fix(auth): SubjectTokenProviderError drops response and duplicates error message in workload identity providers

オープン 初心者向け
#4,017 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@mohmedmm がすでに取り組んでいます。

2026年10月2日 から。

  • #1 @mohmedmm による — オープン

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
86/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
python

調査の方向性

src/openai/auth/_workload.py から始め、k8s_service_account_token_provider、azure_managed_identity_token_provider、gcp_id_token_provider の例外処理を確認してください。上記で説明されているモック HTTP 500 レスポンスで問題を再現し、その後、SubjectTokenProviderError がレスポンスを保持し、重複したメッセージと冗長な例外チェーンを回避することを検証してください。

索引モデルが issue の本文から書いたものです。

説明

Confirm this is an issue with the Python library and not an underlying OpenAI API
  • This is an issue with the Python library
Describe the bug

In src/openai/auth/_workload.py, the built-in workload identity subject token providers (azure_managed_identity_token_provider(), gcp_id_token_provider(), and k8s_service_account_token_provider()) catch their own intentionally raised SubjectTokenProviderError exceptions inside generic except Exception as e: blocks.

This leads to two issues:

  1. Lost response property: SubjectTokenProviderError defines a response: httpx2.Response | None attribute. The provider functions explicitly pass response=response when the metadata server returns an error status (response.is_error) or an empty body. However, the outer except Exception as e: intercepts this error (as SubjectTokenProviderError inherits from OpenAIError -> Exception) and instantiates a brand new SubjectTokenProviderError(...) without passing response, setting err.response to None. Callers attempting to inspect err.response for headers, status codes, or error details receive None.
  2. Duplicated error message prefixes: The re-wrapped exception message duplicates the prefix (e.g. "Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500").
  3. Redundant exception nesting: A SubjectTokenProviderError is chained as the __cause__ of an identical SubjectTokenProviderError.
To Reproduce

Steps:

  1. Initialize azure_managed_identity_token_provider() or gcp_id_token_provider() with an http_client mock returning an HTTP 500 (or non-200) error.
  2. Call provider["get_token"]().
  3. Catch SubjectTokenProviderError and inspect err.response and str(err).
Code snippets
import httpx2
from openai.auth._workload import azure_managed_identity_token_provider
from openai._exceptions import SubjectTokenProviderError

mock_client = httpx2.Client(
    transport=httpx2.MockTransport(lambda req: httpx2.Response(500, text="Internal Server Error"))
)
provider = azure_managed_identity_token_provider(http_client=mock_client)

try:
    provider["get_token"]()
except SubjectTokenProviderError as err:
    print(f"err.response is: {err.response}")  # Actual: None | Expected: <Response [500]>
    print(f"Error message: {err}")
    print(f"err.__cause__: {repr(err.__cause__)}")

Actual Output:

err.response is: None
Error message: Failed to fetch Azure subject token from IMDS: Failed to fetch Azure subject token from IMDS: HTTP 500
err.__cause__: SubjectTokenProviderError('Failed to fetch Azure subject token from IMDS: HTTP 500')

Expected Output:
err.response should retain the <Response [500 Internal Server Error]> object attached when the initial SubjectTokenProviderError was raised, and the error message should not contain duplicated prefixes.

Proposed fix

In src/openai/auth/_workload.py:
In k8s_service_account_token_provider, azure_managed_identity_token_provider, and gcp_id_token_provider, re-raise SubjectTokenProviderError before the generic except Exception block:

        except SubjectTokenProviderError:
            raise
        except Exception as e:
            raise SubjectTokenProviderError(f"...: {e}") from e
OS

All platforms (cross-platform library error handling)

Python version

Python 3.10+

Library version

openai v1.x / latest main

主要言語
Python
スター
31.8k
フォーク
7.3k
平均マージ
1日 3時間
マージ済み PR(30日)
128

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

openai/openai-python のほかの issue

openai/openai-python の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。