fix: treat forwarded OAuth access tokens as ephemeral session state - #7096
Open
copybara-service[bot] wants to merge 1 commit into
Open
fix: treat forwarded OAuth access tokens as ephemeral session state#7096copybara-service[bot] wants to merge 1 commit into
copybara-service[bot] wants to merge 1 commit into
Conversation
Access tokens supplied in `request.authorizations` are now handed to the agent as a `temp:`-prefixed `state_delta` for the duration of the turn, rather than written into the session's initial state. ADK trims `temp:` keys before a session is persisted, so the tokens stay out of durable session storage while remaining readable through `tool_context.state["temp:<auth_id>"]` for the whole invocation, sub-agents included. Agents reading the bare `tool_context.state["<auth_id>"]` key must switch to `temp:<auth_id>`. Requires google-adk >= 1.27.0, the release in which `temp:` state deltas began being applied to the in-memory session before being trimmed. PiperOrigin-RevId: 970111577
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix: treat forwarded OAuth access tokens as ephemeral session state
Access tokens supplied in
request.authorizationsare now handed to the agentas a
temp:-prefixedstate_deltafor the duration of the turn, rather thanwritten into the session's initial state. ADK trims
temp:keys before asession is persisted, so the tokens stay out of durable session storage while
remaining readable through
tool_context.state["temp:<auth_id>"]for the wholeinvocation, sub-agents included.
Agents reading the bare
tool_context.state["<auth_id>"]key must switch totemp:<auth_id>.Requires google-adk >= 1.27.0, the release in which
temp:state deltas beganbeing applied to the in-memory session before being trimmed.