Skip to content

Close the session after the FAB permissions collection read - #72950

Merged
vincbeck merged 1 commit into
apache:mainfrom
bingqin2:fab-permissions-session
Sep 11, 2026
Merged

vincbeck merged 1 commit into
apache:mainfrom
bingqin2:fab-permissions-session

Conversation

@bingqin2

Copy link
Copy Markdown
Contributor

GET /auth/fab/v1/permissions still runs its two queries through security_manager.session, the thread-local scoped session, without ending the transaction. The route is a sync FastAPI handler, so it runs on a threadpool thread, and the Session.remove() that cleanup_session_middleware issues on the event-loop thread never reaches that session. On PostgreSQL the backend stays idle in transaction after the 200 response, which is the leak #72362 describes for the users and roles collections. #72578 fixed those two; this applies the same create_session(scoped=False) block to the permissions collection, the last collection handler in the FAB FastAPI services that read through the scoped session.

Changes

  • providers/fab/src/airflow/providers/fab/auth_manager/api_fastapi/services/roles.py: FABAuthManagerRoles.get_permissions runs inside create_session(scoped=False), like get_roles and get_users
  • providers/fab/tests/unit/fab/auth_manager/api_fastapi/services/test_roles.py: the five get_permissions tests patch create_session and assert the session is entered once and exited, including on the 400 path

Testing

  • providers/fab: tests/unit/fab/auth_manager/api_fastapi/services/test_roles.py and tests/unit/fab/auth_manager/api_fastapi/routes/test_roles.py (54 tests)
  • mypy on the changed module, prek hooks on the changed files (no route or datamodel changes, so the FAB OpenAPI spec is unchanged)

closes: #72362


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

Generated-by: Claude Code (Claude Fable 5.1) following the guidelines. I reviewed and understand all changes; the tests were run locally as listed above.


🤖 Generated with Claude Code

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@vincbeck
vincbeck merged commit 23f8701 into apache:main Sep 11, 2026
79 checks passed
@bingqin2
bingqin2 deleted the fab-permissions-session branch September 13, 2026 05:09
xvega pushed a commit to xvega/airflow that referenced this pull request Sep 13, 2026
dlactin pushed a commit to dlactin/airflow that referenced this pull request Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

providers-fab: GET /auth/fab/v1/users and /roles leave PostgreSQL sessions idle in transaction after #68100

2 participants