Repository navigation
Respect maximum_page_limit in batch list endpoints - #73409
Eason09053360 wants to merge 1 commit into
Conversation
The `[api] maximum_page_limit` cap is documented as applying to any limit a client asks for, but it was only enforced on the query-parameter path, inside `LimitFilter.depends`. The two batch endpoints read their page size from a request body, so FastAPI never invokes that dependency and the cap was never applied — an authenticated client could ask these two endpoints for the whole table while the equivalent GET endpoints capped the same request. Giving the clamp its own name lets both entry points share one definition, so they cannot disagree about the setting again.
|
Hello @Eason09053360 - thank you for your contributions to Apache Airflow! The Airflow community has introduced a limit of 5 open pull requests at a time for contributors without write access to the repository. You currently have 33 open pull requests, so - as a one-time step of introducing the limit - we closed the ones where maintainers have not engaged yet:
These pull requests stay open because maintainers are already engaged in them - they count towards your limit:
This is not a judgement of you or of your changes. We never told contributors before that opening many pull requests at once was a problem, so there is nothing to feel bad about - and nothing is lost: your branches, commits and the review history stay where they are. What we ask you to do is to make your first prioritization decision: choose which of the pull requests above matter most to you, and reopen them (up to 5 open at a time, including the ones still open) with the "Reopen pull request" button or While your pull requests are waiting for review, the most valuable thing you can do is help in other ways - reviewing other contributors' pull requests, helping with issues, and taking part in the discussions on the devlist and Slack. Why we introduced the limit, what it means for you and how to reopen or restore a pull request is explained in https://github.com/apache/airflow/blob/main/contributing-docs/32_open_pull_request_limit.rst. Drafted-by: Claude Code (Opus 5); reviewed by @potiuk before posting |
Why
[api] maximum_page_limitis documented as capping any limit a client asks for, but was only enforced insideLimitFilter.depends, on the query-parameter path. The two batch endpoints (POST /dags/~/dagRuns/list,POST /dags/~/dagRuns/~/taskInstances/list) read their page size from a request body, so FastAPI never invokes that dependency — an authenticated client could ask them for the whole table while the equivalent GET endpoints capped the same request. The cap arrived in #60989, which missed these two call sites.What
LimitFilter.clamp_to_maximumincommon/parameters/base.py;dependsdelegates to it, so both entry points share one definition.LimitFilterthrough it.total_entriesreports the larger unclamped count; both fail without the fix.Was generative AI tooling used to co-author this PR?
Generated-by: Claude Code (Opus 5) following the guidelines