What happened?
InMemoryPushNotificationConfigStore.set_info appends the caller proto and get_info / get_info_for_dispatch return those same objects.
After create/get, changing url/token/id on the request or response proto silently changes the stored webhook. The next send_notification POSTs to the mutated URL.
DatabasePushNotificationConfigStore already CopyFroms. InMemoryTaskStore wraps CopyingTaskStoreAdapter for the same reason. The JS SDK had this class of bug and cloned on save.
Repro
cfg = TaskPushNotificationConfig(url="http://a.example/cb")
await store.set_info("t1", cfg, ctx)
cfg.url = "http://evil.example/cb"
got = await store.get_info("t1", ctx)
Observed: got[0].url == "http://evil.example/cb"
Expected: stored copy still "http://a.example/cb"
Relevant log output
n/a.
Code of Conduct
What happened?
InMemoryPushNotificationConfigStore.set_infoappends the caller proto andget_info/get_info_for_dispatchreturn those same objects.After create/get, changing
url/token/idon the request or response proto silently changes the stored webhook. The nextsend_notificationPOSTs to the mutated URL.DatabasePushNotificationConfigStorealreadyCopyFroms.InMemoryTaskStorewrapsCopyingTaskStoreAdapterfor the same reason. The JS SDK had this class of bug and cloned on save.Repro
Observed:
got[0].url == "http://evil.example/cb"Expected: stored copy still
"http://a.example/cb"Relevant log output
n/a.
Code of Conduct