Repository navigation
deny unknown backfill_id directly instead of falling back to body dag_id - #71114
bujjibabukatta wants to merge 4 commits into
Conversation
7d29917 to
55e28b2
Compare
79953f3 to
f7cedd5
Compare
|
Hello @bujjibabukatta - thank you for your contributions to Apache Airflow! The Airflow community has introduced a limit of 5 open pull requests at a time for contributors without write access to the repository. You currently have 16 open pull requests, so - as a one-time step of introducing the limit - we closed the ones where maintainers have not engaged yet:
These pull requests stay open because maintainers are already engaged in them - they count towards your limit:
This is not a judgement of you or of your changes. We never told contributors before that opening many pull requests at once was a problem, so there is nothing to feel bad about - and nothing is lost: your branches, commits and the review history stay where they are. What we ask you to do is to make your first prioritization decision: choose which of the pull requests above matter most to you, and reopen them (up to 5 open at a time, including the ones still open) with the "Reopen pull request" button or While your pull requests are waiting for review, the most valuable thing you can do is help in other ways - reviewing other contributors' pull requests, helping with issues, and taking part in the discussions on the devlist and Slack. Why we introduced the limit, what it means for you and how to reopen or restore a pull request is explained in https://github.com/apache/airflow/blob/main/contributing-docs/32_open_pull_request_limit.rst. Drafted-by: Claude Code (Opus 5); reviewed by @potiuk before posting |
Summary
Fixes an authorization bug in
requires_access_backfillwhere an unknownbackfill_idcould be distinguished from a forbidden one by response status code, leaking which backfill ids exist.Root Cause
When
backfill_idwas present but matched no row,dag_idstayedNone— the same as when there was nobackfill_idat all — so the check fell through to authorizing against adag_idfrom the request body instead of denying outright.Fix
If
backfill_idis given but matches no row, deny immediately with403 Forbidden(the same response a forbidden-but-existing backfill gets), instead of falling back to the body-supplieddag_id.Closes: #71080
Was generative AI tooling used ?
Generated-by: Claude following the guidelines