Skip to content

providers-fab: close sessions after users and roles collection reads - #72578

Merged
vincbeck merged 5 commits into
apache:mainfrom
MarthalaJagruthiReddy:fix/fab-close-api-query-sessions
Sep 9, 2026
Merged

vincbeck merged 5 commits into
apache:mainfrom
MarthalaJagruthiReddy:fix/fab-close-api-query-sessions

Conversation

@MarthalaJagruthiReddy

Copy link
Copy Markdown

Summary

  • Replace the thread-local FAB security_manager.session in the users and roles collection handlers with explicit create_session(scoped=False) contexts.
  • Materialize Pydantic responses while the session is open, then close the worker-thread session before returning.
  • Add regression assertions that the context manager is created with scoped=False and exited on success and validation errors.

This addresses the sync FastAPI/thread-pool session leak described in #72361 and follows the explicit-session pattern used by Airflow's API code.

Fixes #72361

Testing

  • PYTHONPATH=devel-common/src uv run --project providers/fab --no-dev --with pytest --with pytest-subtests --with pytest-timeout --with time-machine --with pytest-asyncio --with pytest-mock pytest providers/fab/tests/unit/fab/auth_manager/api_fastapi/services/test_users.py providers/fab/tests/unit/fab/auth_manager/api_fastapi/services/test_roles.py -q
  • 47 passed, 1 warning

Use explicit non-scoped sessions for FAB users and roles collection queries so sync FastAPI worker threads close their own PostgreSQL transactions.
Use explicit non-scoped sessions for FAB users and roles collection queries so sync FastAPI worker threads close their own PostgreSQL transactions.
Verify collection queries use a non-scoped session and close it after materializing the response.
Verify role collection queries use a non-scoped session and close it after materializing the response.
@boring-cyborg

boring-cyborg Bot commented Sep 6, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@vincbeck
vincbeck merged commit 0ade0fb into apache:main Sep 9, 2026
79 checks passed
@boring-cyborg

boring-cyborg Bot commented Sep 9, 2026

Copy link
Copy Markdown

Awesome work, congrats on your first merged pull request! You are invited to check our Issue Tracker for additional contributions.

imrichardwu pushed a commit to imrichardwu/airflow that referenced this pull request Sep 11, 2026
…pache#72578)

Use explicit non-scoped sessions for FAB users and roles collection queries so sync FastAPI worker threads close their own PostgreSQL transactions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

providers-fab: GET /auth/fab/v1/users and /roles leave PostgreSQL sessions idle in transaction after #68100

2 participants