-
Type:
Task
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
Component/s: None
-
None
-
None
-
Python Drivers
-
Not Needed
-
-
None
-
None
-
None
-
None
-
None
-
None
Context
- PYTHON-5805 added `kms_connect_callback` (4.19) inline in `encryption.py` and the public types in `encryption_options.py`, but both already very large.
- PYTHON-6147's HTTP proxy helpers add even more kms connect logic and need a dedicated home outside the encryption modules.
- PYTHON-5805 missed the spec's prose tests; they are deferred to the last ticket (PYTHON-6147), which will use the callback helpers to run them.
Definition of done
- The KMS connect plumbing moves out of `encryption.py` into dedicated private modules, giving the shared types and the per-API connect logic a home outside the encryption modules.
- No public API change: the public names remain importable from `encryption_options` and the API docs keep resolving under the public import path.
- Tests consolidate into a single file parametrized over the `[async]`/`[sync]` APIs, and all encryption tests are green.
Pitfalls
- Purely mechanical: preserve the existing behavior exactly.
- The doc build must keep documenting the public types under the `encryption_options` import path.