Skip to content

Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware() - #70783

Open
stephen-bracken wants to merge 1 commit into
apache:mainfrom
stephen-bracken:make-jwt-extendible
Open

stephen-bracken wants to merge 1 commit into
apache:mainfrom
stephen-bracken:make-jwt-extendible

Conversation

@stephen-bracken

@stephen-bracken stephen-bracken commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

closes: #70720

Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()

Refactor the initialisation flow for the JWTRefreshMiddleware to give greater control to auth managers over how this middleware gets initialised.

The current behaviour is preserved by setting the BaseAuthManager.use_jwt_middleware attribute to True (default True).

By moving the JWTRefreshMiddleware initialisation to BaseAuthManager.get_jwt_refresh_middleware(), this allows auth managers to override the JWTRefreshMiddleware behaviour by inheriting from it and using the inherited class in get_fastapi_middlewares instead.

By factoring out the _set_new_token() method from dispatch(), this gives an interface for the inherited token refresh middleware to alter the behaviour of the middleware when setting the tokens. The interface has access to the response object to set any cookies as needed.

Changed the _refresh_user() method to accept a request object to allow accessing any cookies or state information from the request.

Also adds the airflow.api_fastapi.app.request_cookie_is_secure() helper to standardise setting HTTP secure cookies

Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)
  • No

@stephen-bracken stephen-bracken changed the title Make JWTRefreshMiddleware into a standard fastapi middleware Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()` Jul 30, 2026
@stephen-bracken stephen-bracken changed the title Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()` Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware() Jul 30, 2026
@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 3 times, most recently from 474ce7b to 7655032 Compare July 30, 2026 22:56
@stephen-bracken
stephen-bracken marked this pull request as ready for review July 30, 2026 23:38
Comment thread airflow-core/src/airflow/api_fastapi/auth/middlewares/refresh_token.py Outdated
Comment thread airflow-core/src/airflow/api_fastapi/core_api/app.py Outdated
@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 3 times, most recently from 16198fd to 3a89840 Compare July 31, 2026 19:11
@vincbeck

Copy link
Copy Markdown
Contributor

CI is failing

@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 6 times, most recently from a8c2ae1 to 3dc4d12 Compare August 1, 2026 16:29

@pierrejeambrun pierrejeambrun left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How does this work for old provider version (fab) and new core (removing the hardcoded JWTRefreshMiddleware to move it to BaseAuthManager ?
New fab calls super().get_fastapi_middlewares(), old fab do not so the refresh token middleware disappears?

Comment thread airflow-core/src/airflow/api_fastapi/auth/managers/base_auth_manager.py Outdated
Comment thread airflow-core/src/airflow/api_fastapi/app.py Outdated
@stephen-bracken

stephen-bracken commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor Author

How does this work for old provider version (fab) and new core (removing the hardcoded JWTRefreshMiddleware to move it to BaseAuthManager ?
New fab calls super().get_fastapi_middlewares(), old fab do not so the refresh token middleware disappears?

In 3.3.1 and prior versions of airflow the JWTRefreshMiddleware will be injected in the hardcoded initialisation in airflow.api_fastapi.core_api.app.init_middlewares:

app.add_middleware(JWTRefreshMiddleware)

In Airflow v3.3.0 and v3.3.1 BaseAuthManager.get_fastapi_middlewares() returns a [], but after this change it will return [(JWTRefreshMiddleware,{})].

The super().get_fastapi_middlewares() is there to include any middlewares we add to BaseAuthManager in FabAuthManager. This will need to be included in any auth managers that alter get_fastapi_middlewares() if they also use a JWTRefreshMiddleware. the if AIRFLOW_V_3_3_PLUS guard is there because get_fastapi_middlewares() was added in 3.3.0

@stephen-bracken stephen-bracken changed the title Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware() Make JWTRefreshMiddleware extensible via BaseAuthManager._get_jwt_refresh_middleware() Aug 17, 2026
@eladkal
eladkal requested a review from pierrejeambrun August 17, 2026 20:13
@eladkal eladkal modified the milestones: Airflow 3.3.2, Airflow 3.4.0 Aug 18, 2026
@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 2 times, most recently from 3fc88d5 to a96fe18 Compare August 28, 2026 19:03

@pierrejeambrun pierrejeambrun left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In your latest reply, you answer "old core <-> new provider", but my question was more about "old provider <-> new core".

I believe this is breaking the because core no longer hardcode JWTRefreshMiddleware, but old provider doesn't call super().get_fastapi_middlewares().

Can you try this setup loacally and report back.

Comment thread airflow-core/tests/unit/api_fastapi/auth/middlewares/test_refresh_token.py Outdated
@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 6 times, most recently from d0d9932 to 3702205 Compare September 15, 2026 13:47
@stephen-bracken

stephen-bracken commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor Author

@pierrejeambrun

I believe this is breaking the because core no longer hardcode JWTRefreshMiddleware, but old provider doesn't call super().get_fastapi_middlewares().

I have added BaseAuthManager.use_jwt_middleware (default True) that will trigger the old refresh behaviour where necessary. This allows auth managers to control the order in which the middleware from get_jwt_refresh_middleware() gets initialised without breaking old auth flows.

@stephen-bracken
stephen-bracken force-pushed the make-jwt-extendible branch 4 times, most recently from 25b289d to 8dbd6d9 Compare September 15, 2026 16:20
@stephen-bracken stephen-bracken changed the title Make JWTRefreshMiddleware extensible via BaseAuthManager._get_jwt_refresh_middleware() Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware() Sep 16, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make request cookies available to AuthManager methods

4 participants