Skip to content

CreateUserRequest.human.password has the wrong type (SetPassword instead of Password), so CreateUser with a password always fails #145

Description

@gbmerrall

SDK version: zitadel-client 4.1.9 (latest on PyPI)
Python: 3.12
Server: Zitadel Cloud

Description

UserServiceHuman.password (used by UserServiceCreateUserRequest.human) is typed as
UserServiceSetPassword. The server's proto defines that field as Password:

proto/zitadel/user/v2/user_service.proto, in CreateUserRequest.Human:

oneof password_type {
  Password password = 4;
  HashedPassword hashed_password = 5;
}

SetPassword wraps a Password, so the SDK sends one extra level of nesting:

// sent by the SDK
"password": {"password": {"password": "...", "changeRequired": false}}

// expected by the server
"password": {"password": "...", "changeRequired": false}

Because the models are strict, there is no way to build the correct shape with the SDK, so
creating a user with an initial password always fails.

Reproduction

from zitadel_client import Zitadel
from zitadel_client.models import (
    UserServiceCreateUserRequest,
    UserServiceHuman,
    UserServicePassword,
    UserServiceProfile,
    UserServiceSetHumanEmail,
    UserServiceSetPassword,
)

zitadel = Zitadel.with_access_token("https://<instance>", "<PAT>")
zitadel.users.create_user(
    UserServiceCreateUserRequest(
        organization_id="<org id>",
        username="someone@example.com",
        human=UserServiceHuman(
            profile=UserServiceProfile(given_name="Some", family_name="One"),
            email=UserServiceSetHumanEmail(email="someone@example.com", is_verified=True),
            password=UserServiceSetPassword(
                password=UserServicePassword(password="Str0ng!Passw0rd", change_required=False)
            ),
        ),
    )
)

Actual result

ApiError with status 400:

unmarshal message: unmarshal into *user.CreateUserRequest: proto: (line 1:304):
invalid value for string field password: {

Expected result

The user is created with the given password. UserServiceHuman.password should be typed as
UserServicePassword, and hashed_password as UserServiceHashedPassword, matching the proto.

Notes

  • The SDK itself is generated, so the mismatch may come from the OpenAPI spec it is built
    from, or from the generator.
  • UserServiceSetPasswordRequest.new_password is correctly typed as UserServicePassword.
    Our workaround is to call CreateUser without a password, then call SetPassword.
  • It may be worth checking other messages that have a password_type e.g. AddHumanUserRequest

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions