Skip to content

Read the msgraph connection extra with get_async_extra_dejson - #74161

Merged
dabla merged 5 commits into
apache:mainfrom
dabla:feature/msgraph-async-extra-dejson
Oct 4, 2026
Merged

dabla merged 5 commits into
apache:mainfrom
dabla:feature/msgraph-async-extra-dejson

Conversation

@dabla

@dabla dabla commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

KiotaRequestAdapterHook.get_async_conn() deserializes the raw connection extra with json.loads(connection.extra), to avoid extra_dejson, whose secret masking sends to the supervisor synchronously and fails on the event loop (#54350, #55179). That works, but skips masking the extra's individual values (e.g. proxy credentials, client secrets in the extra).

This switches the async path to get_async_extra_dejson() from common.compat (#74147): Connection.aextra_dejson() on Airflow 3.3.2+ (masks asynchronously, #71890), extra_dejson in a worker thread on older versions (safe there: from 3.2 the channel has a thread lock, and on 3.0/3.1 async code only runs in the triggerer, which serializes requests through asend(); #74166 tests this against the real supervisor comms). _build_request_adapter() now receives the deserialized extra instead of parsing it. The deprecated sync get_conn() reads connection.extra_dejson again (review suggestion), so its extra is masked too. Note that #54350 was not fixed in Airflow itself: it was closed through the json.loads workaround in this hook (#55179), and Airflow only made the extra readable on an event loop with #71890 (3.3.2). extra_dejson is safe in get_conn() because it is only called from sync code (nothing in the provider calls it from the async path); calling the deprecated get_conn() from inside an event loop on Airflow < 3.3.2 would hit #54350 again, so use get_async_conn() there.

Tests: a new test asserts get_async_conn() reads the extra through get_async_extra_dejson(); the existing msgraph hook/operator/sensor/trigger tests pass unchanged.


Was generative AI tooling used to co-author this PR?
  • Yes — Claude Opus 5.5

Generated-by: Claude Opus 5.5 following the guidelines

Connection.extra_dejson masks the extra's secrets with a synchronous
call to the supervisor, which raises DeadlockImminentError when a hook
reads it on an event loop with another async call in flight. Airflow
3.3.2+ has Connection.aextra_dejson() (apache#71890), but providers that still
support older versions cannot call it directly, so async hooks fall back
to json.loads(conn.extra) and skip the masking (apache#72130).

get_async_extra_dejson(conn) awaits Connection.aextra_dejson() when it
exists, and otherwise runs extra_dejson in a worker thread, where
blocking on the supervisor is safe, as get_async_connection() does for
get_connection().

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
KiotaRequestAdapterHook.get_async_conn() deserialized the raw extra with
json.loads(connection.extra) to avoid extra_dejson, whose secret masking
is a synchronous call on the event loop. That skipped masking the
extra's values. It now uses common.compat's get_async_extra_dejson(),
which masks them asynchronously on Airflow 3.3.2+ and from a worker
thread on older versions. The deprecated sync get_conn() is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dabla
dabla force-pushed the feature/msgraph-async-extra-dejson branch from fa03e1a to 1705f49 Compare October 3, 2026 13:16
Comment thread providers/microsoft/azure/src/airflow/providers/microsoft/azure/hooks/msgraph.py Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dabla
dabla marked this pull request as ready for review October 3, 2026 13:38
@dabla dabla closed this Oct 4, 2026
@dabla dabla reopened this Oct 4, 2026
@dabla
dabla merged commit 8331bb4 into apache:main Oct 4, 2026
178 of 187 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants