Repository navigation
Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware() - #70783
stephen-bracken wants to merge 1 commit into
Conversation
0fb0bdd to
9502fe9
Compare
JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()`
JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()`JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()
474ce7b to
7655032
Compare
16198fd to
3a89840
Compare
|
CI is failing |
a8c2ae1 to
3dc4d12
Compare
In 3.3.1 and prior versions of airflow the In Airflow v3.3.0 and v3.3.1 The |
JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()JWTRefreshMiddleware extensible via BaseAuthManager._get_jwt_refresh_middleware()
88369fa to
2a7de92
Compare
3fc88d5 to
a96fe18
Compare
9de9f5e to
8c4d2bd
Compare
There was a problem hiding this comment.
In your latest reply, you answer "old core <-> new provider", but my question was more about "old provider <-> new core".
I believe this is breaking the because core no longer hardcode JWTRefreshMiddleware, but old provider doesn't call super().get_fastapi_middlewares().
Can you try this setup loacally and report back.
d0d9932 to
3702205
Compare
I have added |
25b289d to
8dbd6d9
Compare
8dbd6d9 to
aac7cf4
Compare
JWTRefreshMiddleware extensible via BaseAuthManager._get_jwt_refresh_middleware()JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()
aac7cf4 to
4037eb9
Compare
closes: #70720
Make JWTRefreshMiddleware extensible via BaseAuthManager.get_jwt_refresh_middleware()
Refactor the initialisation flow for the
JWTRefreshMiddlewareto give greater control to auth managers over how this middleware gets initialised.The current behaviour is preserved by setting the
BaseAuthManager.use_jwt_middlewareattribute toTrue(defaultTrue).By moving the
JWTRefreshMiddlewareinitialisation toBaseAuthManager.get_jwt_refresh_middleware(), this allows auth managers to override the JWTRefreshMiddleware behaviour by inheriting from it and using the inherited class in get_fastapi_middlewares instead.By factoring out the
_set_new_token()method fromdispatch(), this gives an interface for the inherited token refresh middleware to alter the behaviour of the middleware when setting the tokens. The interface has access to the response object to set any cookies as needed.Changed the
_refresh_user()method to accept arequestobject to allow accessing any cookies or state information from the request.Also adds the
airflow.api_fastapi.app.request_cookie_is_secure()helper to standardise setting HTTP secure cookiesWas generative AI tooling used to co-author this PR?