mirror of
https://github.com/encounter/adk-python.git
synced 2026-07-09 18:19:28 -07:00
Merge https://github.com/google/adk-python/pull/2870 ## Summary Add `token_endpoint_auth_method` field to OAuth2Auth class to allow configuring OAuth2 token endpoint authentication methods. This enables users to specify how the client should authenticate with the authorization server's token endpoint. • Add `token_endpoint_auth_method` field to `OAuth2Auth` with default value `"client_secret_basic"` • Update `create_oauth2_session()` to pass the authentication method to `OAuth2Session` • Maintain backward compatibility with existing OAuth2 configurations ## Unit Tests Added unit test coverage with 3 new test methods: 1. `test_create_oauth2_session_with_token_endpoint_auth_method()` - Tests explicit auth method setting (`client_secret_post`) 2. `test_create_oauth2_session_with_default_token_endpoint_auth_method()` - Tests default behavior (`client_secret_basic`) 3. `test_create_oauth2_session_oauth2_scheme_with_token_endpoint_auth_method()` - Tests with OAuth2 scheme using `client_secret_jwt` **Test Results:** ✅ 16/16 OAuth2 credential utility tests passed ✅ 240/240 auth module tests passed (no regressions) ✅ Tests cover both GOOGLE_AI and VERTEX variants ✅ Pylint score: 9.41/10 ## Changes Made **src/google/adk/auth/auth_credential.py** - Added `token_endpoint_auth_method: Optional[str] = "client_secret_basic"` to `OAuth2Auth` class **src/google/adk/auth/oauth2_credential_util.py** - Updated `create_oauth2_session()` to pass `token_endpoint_auth_method` parameter to `OAuth2Session` **tests/unittests/auth/test_oauth2_credential_util.py** - Added 3 comprehensive test methods covering different authentication scenarios ## Backward Compatibility ✅ **Non-breaking change** - All existing OAuth2 configurations continue to work unchanged with the default `client_secret_basic` authentication method. ## Supported Authentication Methods - `client_secret_basic` (default) - Client credentials in Authorization header - `client_secret_post` - Client credentials in request body - `client_secret_jwt` - JWT with client secret - `private_key_jwt` - JWT with private key Co-authored-by: Xiang (Sean) Zhou <seanzhougoogle@google.com> COPYBARA_INTEGRATE_REVIEW=https://github.com/google/adk-python/pull/2870 from sully90:feat/oauth2-token-endpoint-auth-method 04fe8244598f96b4e3366f0fc79382628382e9c2 PiperOrigin-RevId: 843739984