Repository navigation
fix(server): warn when an AgentCard is missing required fields - #1279
Merged
Iwaniukooo11 merged 2 commits intoOct 7, 2026
Merged
Conversation
🧪 Code Coverage (vs
|
| Base | PR | Delta | |
|---|---|---|---|
| src/a2a/server/cluster/database_event_stream.py | 92.86% | 96.94% | 🟢 +4.08% |
| src/a2a/server/request_handlers/default_request_handler.py | 97.95% | 97.96% | 🟢 +0.01% |
| src/a2a/server/request_handlers/default_request_handler_v2.py | 87.50% | 87.46% | 🔴 -0.04% |
| src/a2a/utils/proto_utils.py | 91.20% | 95.65% | 🟢 +4.45% |
| Total | 93.00% | 93.14% | 🟢 +0.14% |
Generated by coverage-comment.yml
Patrick-SCH03
force-pushed
the
fix/warn-invalid-agent-card
branch
from
September 29, 2026 17:19
484bc72 to
da74a47
Compare
Member
|
Thanks @Patrick-SCH03 You deliberately skipped Same for signing - please add a I left request changes - Please review them. Then we are free to merge:) Once again, thanks for you contribution |
Iwaniukooo11
requested changes
Oct 7, 2026
AgentCard marks eight fields REQUIRED, but nothing checks them, so an
empty card is served as `{}`. As the first, non-breaking step suggested
in a2aproject#1267, log a warning listing the missing fields when a card is passed
to create_agent_card_routes, DefaultRequestHandler or
DefaultRequestHandlerV2 (agent_card and extended_agent_card). The check
runs once at setup, never raises, and skips objects that are not
Protobuf messages such as test doubles.
Fixes a2aproject#1267
…ving and signing Address review on a2aproject#1279: - Explain in the warning that a non-compliant card is still accepted but may not verify or interoperate across SDKs and could be rejected in a future major release, link to spec section 5.7, and say "missing or empty". - Also warn in agent_card_to_dict and signing._canonicalize_agent_card.
Patrick-SCH03
force-pushed
the
fix/warn-invalid-agent-card
branch
from
October 7, 2026 14:46
da74a47 to
8fe8a93
Compare
Contributor
Author
|
Thanks for the review, @Iwaniukooo11! Addressed in 8fe8a93:
I also rebased onto the latest |
Iwaniukooo11
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
AgentCardmarks eight fieldsREQUIRED, but nothing in the SDK checks them, so an emptyAgentCard()is served as{}with HTTP 200. Following the "suggested first step" in #1267, this logs a warning instead of raising, so existing non-compliant cards keep working while the problem becomes visible.Changes
a2a.utils.proto_utils.warn_on_missing_required_fields(msg, source) -> bool: runs the existing required-field check (_validate_proto_required_fields_internal) and logs oneWARNINGlisting the fields that are missing or empty, including nested paths such asskills[0].tags. It never raises and returns whether the message was complete. Objects that are not Protobuf messages are skipped: an existing test intest_default_request_handler.pypasses a non-card object asagent_card, and user code does the same with test doubles, so a warning helper must not turn that into anAttributeError.create_agent_card_routes(agent_card=...)DefaultRequestHandler.__init__andDefaultRequestHandlerV2.__init__foragent_cardand, when given,extended_agent_cardagent_card_to_dict, which serializes every served card (including cards fromcard_modifier/extended_card_modifier), so this one logs per request; it can be silenced through thea2a.utils.proto_utilsloggersigning._canonicalize_agent_card, used when signing and verifying a cardFor an empty card the log reads:
Enforcement (raising) is left for a major version, as the issue suggests.
Tests (
uv run pytest)tests/utils/test_proto_utils.py: complete message returnsTruewith no log; empty message returnsFalseand logs the exact message instead of raising; an empty repeated field is reported; nested paths are reported.tests/server/routes/test_agent_card_routes.py: an incomplete card logs a warning and is still served with 200; a complete card logs nothing.tests/server/request_handlers/test_default_request_handler.pyand..._v2.py: incompleteagent_cardandextended_agent_cardeach log one warning; complete cards log nothing.tests/server/request_handlers/test_response_helpers.py:agent_card_to_dictwarns for an incomplete card and stays silent for a complete one.tests/utils/test_signing.py:_canonicalize_agent_cardwarns for an incomplete card.mainand pass with this change.bash scripts/lint.sh(ruff check, ruff format, ty) passes.uv run pytest --ignore=tests/integration: 1829 passed, 169 skipped, 3 xfailed.tests/integrationtests that spawn server subprocesses fail identically onmain, so I relied on CI for those.CONTRIBUTINGGuide.bash scripts/format.shfrom the repository root to format)Fixes #1267 🦕