-
Notifications
You must be signed in to change notification settings - Fork 14.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[AIRFLOW-2884] Fix Flask SECRET_KEY security issue in www_rbac #3729
Conversation
The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809)
Codecov Report
@@ Coverage Diff @@
## master #3729 +/- ##
=========================================
+ Coverage 77.46% 77.66% +0.2%
=========================================
Files 204 204
Lines 15822 15825 +3
=========================================
+ Hits 12256 12290 +34
+ Misses 3566 3535 -31
Continue to review full report at Codecov.
|
Hi @kaxil , I have realised this method will cause CSRF error But I think it's still very necessary to have I will raise a separate PR to address this and ping you then. Sorry for the inconvenience caused. |
Thanks @kaxil |
…e#3729) The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809)
…e#3729) The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809)
…e#3729) The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809) (cherry picked from commit fe6d00a) (cherry picked from commit a8900fa) (cherry picked from commit 5b08ec2c3b5b0e67dcdd176a5b3ecbd6f0318a6e)
…e#3729) The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809) (cherry picked from commit fe6d00a) (cherry picked from commit a8900fa) (cherry picked from commit 5b08ec2c3b5b0e67dcdd176a5b3ecbd6f0318a6e) (cherry picked from commit b3711ff)
…e#3729) The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809) (cherry picked from commit fe6d00a) (cherry picked from commit a8900fa)
- BugFix: Tasks with ``depends_on_past`` or ``task_concurrency`` are stuck (apache#12663) - Fix issue with empty Resources in executor_config (apache#12633) - Fix: Deprecated config ``force_log_out_after`` was not used (apache#12661) - Fix empty asctime field in JSON formatted logs (apache#10515) - [AIRFLOW-2809] Fix security issue regarding Flask SECRET_KEY (apache#3651) - [AIRFLOW-2884] Fix Flask SECRET_KEY security issue in www_rbac (apache#3729) - [AIRFLOW-2886] Generate random Flask SECRET_KEY in default config (apache#3738) - Add missing comma in setup.py (apache#12790) - Bugfix: Unable to import Airflow plugins on Python 3.8 (apache#12859) - Fix setup.py missing comma in ``setup_requires`` (apache#12880) - Don't emit first_task_scheduling_delay metric for only-once dags (apache#12835) - Update setup.py to get non-conflicting set of dependencies (apache#12636) - Rename ``[scheduler] max_threads`` to ``[scheduler] parsing_processes`` (apache#12605) - Add metric for scheduling delay between first run task & expected start time (apache#9544) - Add new-style 2.0 command names for Airflow 1.10.x (apache#12725) - Add Kubernetes cleanup-pods CLI command for Helm Chart (apache#11802) - Don't let webserver run with dangerous config (apache#12747) - Replace pkg_resources with importlib.metadata to avoid VersionConflict errors (apache#12694) - Clarified information about supported Databases
The same issue was fixed for /www previously in PR apache#3651 (JIRA ticket 2809) (cherry picked from commit fe6d00a)
Jira
Description
The same issue was fixed for
/www
previously in PR #3651 , (JIRA ticket 2809, https://issues.apache.org/jira/browse/AIRFLOW-2809)This commit is to fix the same issue for
/www_rbac
.In addition, updated the comment in
airflow/config_templates/default_airflow.cfg
.Tests
Commits
Documentation
Code Quality
git diff upstream/master -u -- "*.py" | flake8 --diff