Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

`google.api.Service` config seems to require an audience to avoid JWT validation errors

Aberta
#6,077 5 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 5 dias

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
38/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Estagnada
Stack de tecnologia
python
Domínio
api, authentication

Direção de pesquisa

Comece por endpoints/bookstore-grpc/api_config_auth.yaml e endpoints/bookstore-grpc-transcoding/api_config_auth.yaml e, em seguida, examine jwt_token_gen.py e bookstore_client.py quanto ao fluxo de autenticação. Reproduza a solicitação JWT descrita na issue e verifique se ambas as configurações de serviço aceitam a autenticação pretendida da conta de serviço sem o erro de validação do audience.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

api: auth samples type: process

In which file did you encounter the issue?

Did you change the file? If so, how?

Yes, in the following section of the files:

#
# Request authentication.
#
authentication:
  providers:
  - id: google_service_account
    # Replace SERVICE-ACCOUNT-ID with your service account's email address.
    issuer: SERVICE-ACCOUNT-ID
    jwks_uri: https://www.googleapis.com/robot/v1/metadata/x509/SERVICE-ACCOUNT-ID
  rules:
  # This auth rule will apply to all methods.
  - selector: "*"
    requirements:
      - provider_id: google_service_account

I added an audience field to the config:

#
# Request authentication.
#
authentication:
  providers:
  - id: google_service_account
    # Replace SERVICE-ACCOUNT-ID with your service account's email address.
    issuer: SERVICE-ACCOUNT-ID
    jwks_uri: https://www.googleapis.com/robot/v1/metadata/x509/SERVICE-ACCOUNT-ID
    audiences: DEFAULT_HOSTNAME
  rules:
  # This auth rule will apply to all methods.
  - selector: "*"
    requirements:
      - provider_id: google_service_account

Describe the issue

When using current api_config_auth.yaml for service-account JWT authentication I continued to get "{"message":"Audiences in Jwt are not allowed","code":403}". This error was present regardless of whether the JWT I passed had an audience. I used jwt_token_gen.py to generate the JWTs to pass when reaching out to the api python3 bookstore_client.py --auth_token JWT_TOKEN --host= DEFAULT_HOSTNAME --port 443 --use_tls true.

To generate a JWT without an audience field I commented out the 'aud' portion of the payload in jwt_token_gen.py . I tried without an audience and with the service name as an audience and each test provided the same error message. I inspected each JWT in jwt.io to ensure that each JWT claim was how I expected.

Overall, I suspect the google.api.Service spec has a different behavior for expected audiences than the OpenAPI spec (which doesn't required audience). Adding audience to the config resolved the issue and allowed me to hit the API with service-account JWT authentication enabled. Willing to create a PR to incorporate audiences: DEFAULT_HOSTNAME if approved 👍

Linguagem predominante
Jupyter Notebook
Estrelas
8.1k
Forks
6.7k
Merge médio
4d 12h
PRs com merge (30d)
9

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de GoogleCloudPlatform/python-docs-samples

Todas as issues de GoogleCloudPlatform/python-docs-samples

Issues semelhantes

Mais issues de Backend & API Design

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.