Skip to content

fix(server): warn when an AgentCard is missing required fields - #1279

Merged
Iwaniukooo11 merged 2 commits into
a2aproject:mainfrom
Patrick-SCH03:fix/warn-invalid-agent-card
Oct 7, 2026
Merged

Iwaniukooo11 merged 2 commits into
a2aproject:mainfrom
Patrick-SCH03:fix/warn-invalid-agent-card

Conversation

@Patrick-SCH03

@Patrick-SCH03 Patrick-SCH03 commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description

AgentCard marks eight fields REQUIRED, but nothing in the SDK checks them, so an empty AgentCard() is served as {} with HTTP 200. Following the "suggested first step" in #1267, this logs a warning instead of raising, so existing non-compliant cards keep working while the problem becomes visible.

Changes

  • a2a.utils.proto_utils.warn_on_missing_required_fields(msg, source) -> bool: runs the existing required-field check (_validate_proto_required_fields_internal) and logs one WARNING listing the fields that are missing or empty, including nested paths such as skills[0].tags. It never raises and returns whether the message was complete. Objects that are not Protobuf messages are skipped: an existing test in test_default_request_handler.py passes a non-card object as agent_card, and user code does the same with test doubles, so a warning helper must not turn that into an AttributeError.
  • Called where a card enters or leaves the SDK:
    • create_agent_card_routes(agent_card=...)
    • DefaultRequestHandler.__init__ and DefaultRequestHandlerV2.__init__ for agent_card and, when given, extended_agent_card
    • agent_card_to_dict, which serializes every served card (including cards from card_modifier / extended_card_modifier), so this one logs per request; it can be silenced through the a2a.utils.proto_utils logger
    • signing._canonicalize_agent_card, used when signing and verifying a card

For an empty card the log reads:

agent_card passed to create_agent_card_routes: AgentCard is not spec-compliant - REQUIRED fields missing or empty: name, description, supported_interfaces, version, capabilities, default_input_modes, default_output_modes, skills. This is allowed and does not raise, but it may not verify or interoperate across SDKs and could be rejected in a future major release. See https://a2a-protocol.org/latest/specification/#57-field-presence-and-optionality

Enforcement (raising) is left for a major version, as the issue suggests.

Tests (uv run pytest)

  • tests/utils/test_proto_utils.py: complete message returns True with no log; empty message returns False and logs the exact message instead of raising; an empty repeated field is reported; nested paths are reported.
  • tests/server/routes/test_agent_card_routes.py: an incomplete card logs a warning and is still served with 200; a complete card logs nothing.
  • tests/server/request_handlers/test_default_request_handler.py and ..._v2.py: incomplete agent_card and extended_agent_card each log one warning; complete cards log nothing.
  • tests/server/request_handlers/test_response_helpers.py: agent_card_to_dict warns for an incomplete card and stays silent for a complete one.
  • tests/utils/test_signing.py: _canonicalize_agent_card warns for an incomplete card.
  • The warning-asserting tests fail on main and pass with this change.
  • bash scripts/lint.sh (ruff check, ruff format, ty) passes.
  • uv run pytest --ignore=tests/integration: 1829 passed, 169 skipped, 3 xfailed.
  • On Windows, some tests/integration tests that spawn server subprocesses fail identically on main, so I relied on CI for those.

Fixes #1267 🦕

@Patrick-SCH03
Patrick-SCH03 requested a review from a team as a code owner September 25, 2026 14:04
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

🧪 Code Coverage (vs main)

⬇️ Download Full Report

Base PR Delta
src/a2a/server/cluster/database_event_stream.py 92.86% 96.94% 🟢 +4.08%
src/a2a/server/request_handlers/default_request_handler.py 97.95% 97.96% 🟢 +0.01%
src/a2a/server/request_handlers/default_request_handler_v2.py 87.50% 87.46% 🔴 -0.04%
src/a2a/utils/proto_utils.py 91.20% 95.65% 🟢 +4.45%
Total 93.00% 93.14% 🟢 +0.14%

Generated by coverage-comment.yml

@Patrick-SCH03
Patrick-SCH03 force-pushed the fix/warn-invalid-agent-card branch from 484bc72 to da74a47 Compare September 29, 2026 17:19
@Iwaniukooo11 Iwaniukooo11 self-assigned this Oct 7, 2026
@Iwaniukooo11

Iwaniukooo11 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Thanks @Patrick-SCH03

You deliberately skipped agent_card_to_dict, but it should warn there too (the per-request noise is fine and silenceable via the a2a.utils.proto_utils logger).

Same for signing - please add a warn_on_missing_required_fields(...) in signing._canonicalize_agent_card, since the parent issue's scope has changed to cover it.

I left request changes - Please review them. Then we are free to merge:)

Once again, thanks for you contribution

Comment thread src/a2a/utils/proto_utils.py Outdated
Comment thread src/a2a/utils/proto_utils.py Outdated
AgentCard marks eight fields REQUIRED, but nothing checks them, so an
empty card is served as `{}`. As the first, non-breaking step suggested
in a2aproject#1267, log a warning listing the missing fields when a card is passed
to create_agent_card_routes, DefaultRequestHandler or
DefaultRequestHandlerV2 (agent_card and extended_agent_card). The check
runs once at setup, never raises, and skips objects that are not
Protobuf messages such as test doubles.

Fixes a2aproject#1267
…ving and signing

Address review on a2aproject#1279:
- Explain in the warning that a non-compliant card is still accepted but may
  not verify or interoperate across SDKs and could be rejected in a future
  major release, link to spec section 5.7, and say "missing or empty".
- Also warn in agent_card_to_dict and signing._canonicalize_agent_card.
@Patrick-SCH03

Copy link
Copy Markdown
Contributor Author

Thanks for the review, @Iwaniukooo11! Addressed in 8fe8a93:

  • The warning now says the card is not spec-compliant, lists the REQUIRED fields that are missing or empty, explains that this is allowed and does not raise but may not verify or interoperate across SDKs and could be enforced in a future major release, and links to spec section 5.7.
  • agent_card_to_dict and signing._canonicalize_agent_card now warn as well, with tests for both.

I also rebased onto the latest main to resolve the conflict. The PR description is updated to match.

@Iwaniukooo11
Iwaniukooo11 merged commit 4f4101c into a2aproject:main Oct 7, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: AgentCard REQUIRED fields are never validated

2 participants