Skip to content

deny unknown backfill_id directly instead of falling back to body dag_id - #71114

Closed
bujjibabukatta wants to merge 4 commits into
apache:mainfrom
bujjibabukatta:fix/#71080
Closed

bujjibabukatta wants to merge 4 commits into
apache:mainfrom
bujjibabukatta:fix/#71080

Conversation

@bujjibabukatta

Copy link
Copy Markdown
Contributor

Summary

Fixes an authorization bug in requires_access_backfill where an unknown backfill_id could be distinguished from a forbidden one by response status code, leaking which backfill ids exist.

Root Cause

When backfill_id was present but matched no row, dag_id stayed None — the same as when there was no backfill_id at all — so the check fell through to authorizing against a dag_id from the request body instead of denying outright.

Fix

If backfill_id is given but matches no row, deny immediately with 403 Forbidden (the same response a forbidden-but-existing backfill gets), instead of falling back to the body-supplied dag_id.

Closes: #71080

Was generative AI tooling used ?

  • Yes - Claude

Generated-by: Claude following the guidelines

@boring-cyborg boring-cyborg Bot added the area:API Airflow's REST/HTTP API label Aug 4, 2026
@bujjibabukatta bujjibabukatta changed the title fix: deny unknown backfill_id directly instead of falling back to bod… fix: deny unknown backfill_id directly instead of falling back to body dag_id Aug 4, 2026
@bujjibabukatta bujjibabukatta changed the title fix: deny unknown backfill_id directly instead of falling back to body dag_id deny unknown backfill_id directly instead of falling back to body dag_id Aug 4, 2026
@potiuk potiuk added the ready for maintainer review Set after triaging when all criteria pass. label Aug 13, 2026
@potiuk

potiuk commented Sep 25, 2026

Copy link
Copy Markdown
Member

Hello @bujjibabukatta - thank you for your contributions to Apache Airflow!

The Airflow community has introduced a limit of 5 open pull requests at a time for contributors without write access to the repository. You currently have 16 open pull requests, so - as a one-time step of introducing the limit - we closed the ones where maintainers have not engaged yet:

These pull requests stay open because maintainers are already engaged in them - they count towards your limit:

This is not a judgement of you or of your changes. We never told contributors before that opening many pull requests at once was a problem, so there is nothing to feel bad about - and nothing is lost: your branches, commits and the review history stay where they are.

What we ask you to do is to make your first prioritization decision: choose which of the pull requests above matter most to you, and reopen them (up to 5 open at a time, including the ones still open) with the "Reopen pull request" button or gh pr reopen <PR_NUMBER> --repo apache/airflow. Reopen the ones you are ready to follow through - keep them rebased, respond to review comments and fix failing checks.

While your pull requests are waiting for review, the most valuable thing you can do is help in other ways - reviewing other contributors' pull requests, helping with issues, and taking part in the discussions on the devlist and Slack.

Why we introduced the limit, what it means for you and how to reopen or restore a pull request is explained in https://github.com/apache/airflow/blob/main/contributing-docs/32_open_pull_request_limit.rst.


Drafted-by: Claude Code (Opus 5); reviewed by @potiuk before posting

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API closed because of open PR limit Closed as a one-time step of introducing the open pull request limit ready for maintainer review Set after triaging when all criteria pass.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Backfill authorization falls back to the request body when the backfill does not exist

2 participants