Skip to content

OIDC + Python3 + Incorrect padding during base64decode #525

Description

@nabadger

Using 3.6.5

  File "/usr/lib/python3.6/site-packages/kubernetes-6.0.0_snapshot-py3.6.egg/kubernetes/config/kube_config.py", line 474, in load_kube_config
  File "/usr/lib/python3.6/site-packages/kubernetes-6.0.0_snapshot-py3.6.egg/kubernetes/config/kube_config.py", line 355, in load_and_set
  File "/usr/lib/python3.6/site-packages/kubernetes-6.0.0_snapshot-py3.6.egg/kubernetes/config/kube_config.py", line 185, in _load_authentication
  File "/usr/lib/python3.6/site-packages/kubernetes-6.0.0_snapshot-py3.6.egg/kubernetes/config/kube_config.py", line 237, in _load_oid_token
  File "/usr/lib/python3.6/base64.py", line 87, in b64decode
    return binascii.a2b_base64(s)
binascii.Error: Incorrect padding

When attempting to decode the token, I run into this issue in _load_oid_token

  if PY3:
    jwt_attributes = json.loads(
      base64.b64decode(parts[1]).decode('utf-8')
    )

The non py3 block appends "==" to the token part before decoding it. If i use that, it works fine.

Activity

  1. bcatubig commented on May 22, 2018

    @bcatubig

    Ran into this issue today as well on 3.6.4

  2. richerve commented on Aug 8, 2018

    @richerve

    Same on 3.5.5 and 3.6.6.

    This is the reference to the PR to fix this: kubernetes-client/python-base#70

  3. markuszoeller commented on Aug 16, 2018

    @markuszoeller

    Same on Python 3.4

  4. zybjcdl commented on Aug 22, 2018

    @zybjcdl

    @bpicolo Could you please help to fix the issue? We need to run python 3.6.5 with this client.

  5. cparedes commented on Nov 13, 2018

    @cparedes

    Ran into the same issue with Python 3.7 with the latest version of this client (8.0.0 at this time of writing)

  6. AlexShemeshWix commented on Jan 2, 2019

    @AlexShemeshWix

    Same on 3.7.2 and 3.6.0

  7. rocktavious commented on Mar 25, 2019

    @rocktavious

    Same on python 3.7.2 + kubernetes 9.0.0

  8. joshbranham commented on Mar 28, 2019

    @joshbranham

    Anyone know why no fix for this has been merged?

  9. nabadger commented on Mar 29, 2019

    @nabadger
    Author

    @yliaog - would you (or any owner) be able to provide a comment on this? Just wondering what your thoughts are on this issue as it's been around for a while and probably affecting quite a large user base.

  10. yliaog commented on Apr 1, 2019

    @yliaog
    Contributor

    it looks @micw523 is reviewing the fix PR kubernetes-client/python-base#70, @micw523 do you have any further comment on the PR? we'd like to get it merged soon. Thanks.

  11. yliaog commented on Apr 1, 2019

    @yliaog
    Contributor

    /cc

  12. micw523 commented on Apr 1, 2019

    @micw523
    Contributor

    Hi @yliaog, kubernetes-client/python-base#70 seems to have been abandoned and the fork does not exist any more. kubernetes-client/python-base#79 is active and seems like the author just pushed some new commits.

    However, due to the new version of minikube, we need to have #797 merged first to unblock the PRs. We can’t have the CI to pass unless we get that one through.

  13. yliaog commented on Apr 1, 2019

    @yliaog
    Contributor

    Thanks @micw523 i've lgtm'ed #797

    and minor correction, the PR actively worked on is in python-base repo:
    kubernetes-client/python-base#79

  14. switchboardOp commented on Apr 15, 2019

    @switchboardOp

    #797 has merged and it looks like kubernetes-client/python-base#79 passed CI...
    Just waiting on approval there?

  15. TechnoTaff commented on May 16, 2019

    @TechnoTaff

    Can I bump this? My existing code is Python 3.6 and I can't port it back to 2.x due to other libraries. The PR works for me, can we get it pushed into PyPi plz? Thank you.

  16. AlexShemeshWix commented on May 21, 2019

    @AlexShemeshWix

    Any updates?

  17. roycaihw commented on May 23, 2019

    @roycaihw
    Member
  18. r0fls commented on Jun 19, 2019

    @r0fls

    Is there any workaround? 🤔

  19. roycaihw commented on Jun 19, 2019

    @roycaihw
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions