Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Bug: REST catalog auth cannot be configured via environment variables unless auth JSON strings are decoded

Aberta
#3,422 1 comentário 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

@GayathriSrividya já está trabalhando nisso.

Desde 28/5/2026.

  • #3423 de @GayathriSrividya — aberto

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
55/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Pouca atividade
Stack de tecnologia
python

Direção de pesquisa

Comece lendo RestCatalog._create_session() e Config._from_environment_variables() e, em seguida, reproduza os exemplos documentados de variáveis de ambiente de autenticação REST. Adicione cobertura de regressão para a representação compatível das variáveis de ambiente e verifique se a inicialização do catálogo chega ao gerenciador de autenticação configurado sem tratar auth como uma string inutilizável ou como um mapping de chaves separadas por pontos.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Apache Iceberg version

None

Please describe the bug 🐞
Summary

RestCatalog._create_session() expects auth to be a dict. When catalog config comes from environment variables, values are strings, so auth is received as a string and auth initialization fails.

This blocks env-var-based configuration for pluggable REST auth (basic, oauth2, google, entra, custom) unless string JSON is explicitly decoded first.

Minimal repro
export PYICEBERG_CATALOG__REST__TYPE=rest
export PYICEBERG_CATALOG__REST__URI=http://localhost:8181
export PYICEBERG_CATALOG__REST__AUTH='{"type":"oauth2","oauth2":{"client_id":"id","client_secret":"secret","token_url":"https://auth.example/token"}}'
from pyiceberg.catalog import load_catalog
load_catalog("rest")
Actual (without this fix)

Expected: catalog initializes and uses the configured auth manager.

Actual: initialization fails because auth is treated as a string and .get(...) is called on it.

Suggested fix

In REST catalog session setup, if auth is a string, decode it as JSON before reading auth.type and type-specific config.

Add regression tests for both:

  • PYICEBERG_CATALOG__<NAME>__AUTH (JSON string) initializes auth manager correctly.
  • PYICEBERG_CATALOG__<NAME>__AUTH__... maps correctly into auth manager configuration.
Alternative fix (follows current env-var standard)

Support flattened auth properties from environment variables instead of requiring a JSON blob in ...__AUTH.

Example:

export PYICEBERG_CATALOG__REST__AUTH__TYPE=oauth2
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_ID=id
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_SECRET=secret
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__TOKEN_URL=https://auth.example/token

This aligns with existing flattened env-var configuration behavior and avoids JSON-in-env quoting/escaping issues.

Verification

Observed with current code path (Config._from_environment_variables):

export PYICEBERG_CATALOG__REST__AUTH__TYPE=oauth2
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_ID=id
export PYICEBERG_CATALOG__REST__AUTH__OAUTH2__CLIENT_SECRET=secret

Parsed result:

{'catalog': {'rest': {'auth.type': 'oauth2', 'auth.oauth2.client-id': 'id', 'auth.oauth2.client-secret': 'secret'}}}

This confirms flattened AUTH__... env vars are currently stored as dotted keys, not as a nested auth object consumed by RestCatalog._create_session().

Willingness to contribute
  • I can contribute a fix for this bug independently
  • I would be willing to contribute a fix for this bug with guidance from the Iceberg community
  • I cannot contribute a fix for this bug at this time
Linguagem predominante
Python
Estrelas
1.1k
Forks
606
Merge médio
1d 10h
PRs com merge (30d)
72

Preparar o ambiente

  • Sem Dockerfile nem arquivo Docker Compose
  • Tem um modelo de pull request
  • Sem guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de apache/iceberg-python

Todas as issues de apache/iceberg-python

Issues semelhantes

Mais issues de Python

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.