Skip to content

fix: key Eventarc publisher client cache by source principal for impersonated credentials - #7364

Open
ibondarenko1 wants to merge 3 commits into
google:mainfrom
ibondarenko1:eventarc-impersonation-cache-key
Open

ibondarenko1 wants to merge 3 commits into
google:mainfrom
ibondarenko1:eventarc-impersonation-cache-key

Conversation

@ibondarenko1

Copy link
Copy Markdown

Problem

_get_credential_id() in the Eventarc client returns only the target service_account_email for google.auth.impersonated_credentials.Credentials. Two different source principals impersonating the same target service account therefore produce the same cache key and share one cached PublisherAsyncClient, so the second caller publishes using the first caller's source credentials.

Fix

For impersonated credentials, the credential id now includes the source principal: Impersonated:<target>:<id of source credentials>. If the source cannot be determined, it falls back to id(credentials), so no sharing occurs.

Tests

Updated the existing impersonated-credentials assertion to use an explicit source credential. Added test_impersonated_credentials_are_keyed_by_source_principal: the same source gives equal ids, a different source gives different ids, and _get_cache_key differs between them. tests/unittests/integrations/eventarc: 64 passed. The new test fails without the fix.

…rsonated credentials

_get_credential_id() returned only the target service account email for impersonated credentials. Two callers with different source principals that impersonate the same target therefore shared one cached PublisherAsyncClient, so a caller that cannot impersonate the target could publish through a client bound to another caller's authorized credential.

Include the source credentials' identity in the key so each source principal gets its own client.
Added a test for impersonated credentials to verify that they are keyed by source principal and that the credential ID is correctly generated based on the source.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants