Skip to content

fix: read SAFE_TRANSACTION_SERVICE_API_KEY when api_key is not provided - #2766

Open
Amine E. (aelmanaa) wants to merge 1 commit into
safe-global:mainfrom
aelmanaa:fix/tx-service-api-key-env
Open

Amine E. (aelmanaa) wants to merge 1 commit into
safe-global:mainfrom
aelmanaa:fix/tx-service-api-key-env

Conversation

@aelmanaa

Copy link
Copy Markdown

Fixes #2764

TransactionServiceApi.__init__ read SAFE_TRANSACTION_SERVICE_API_KEY as a default argument, so it was evaluated once at import time, and SafeBaseAPI.from_ethereum_client always passes api_key=None, which dropped it entirely. This makes api_key default to None and reads the variable when the instance is created if no key is given, so both the constructor and from_ethereum_client pick it up. An explicitly passed api_key still wins, and the signature is unchanged for callers.

Tests: TestTransactionServiceApiKey covers the key from the environment (constructor and from_ethereum_client, including the Authorization header), an explicit key overriding the environment, and no key. It runs without a Transaction Service API key or network, unlike TestTransactionServiceAPI, which skips when SAFE_TRANSACTION_SERVICE_API_KEY is unset.

Verification (Python 3.13, docker compose up -d db ganache):

This was written with Claude Code; I reviewed and tested it.

`TransactionServiceApi` read the environment variable as a default argument,
so it was evaluated once at import time, and `from_ethereum_client` always
passed `api_key=None` explicitly, which dropped it entirely. Read the
variable when the instance is created if no api key is provided.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aelmanaa
Amine E. (aelmanaa) requested a review from a team as a code owner September 29, 2026 15:06
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@datadog-official

datadog-official Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Pipelines

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 1 Pipeline job failed

CLA Assistant | CLAssistant

View more details · View in GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: d1c3ccd | Docs | View more details | Give us feedback!

@aelmanaa

Copy link
Copy Markdown
Author

Before signing: the CLA link in the bot comment and in CONTRIBUTING (https://safe.global/cla) currently returns 404 (also www.safe.global/cla and /legal/cla), so I can't review the agreement. Could you share where the current CLA text lives? I'll sign for this PR and #2767 (and safe-global/safe-core-sdk#1439) once I've read it. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TransactionServiceApi.from_ethereum_client ignores SAFE_TRANSACTION_SERVICE_API_KEY

1 participant