Skip to content

Create a Middleware that prevent Regexp in the Requests #47364

@bugraoz93

Description

@bugraoz93

Description

Enhance security by eliminating regexp usage in any of the requests. Even if someone is trying to send regexp in str fields, we should return a proper error message that regexp isn't allowed.
https://fastapi.tiangolo.com/tutorial/middleware/#create-a-middleware

Use case/motivation

https://lists.apache.org/thread/xtzdp4dx8s6dds4xdp9kdpohns9lvpst

Related issues

Followup: #46971

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Metadata

Metadata

Assignees

Labels

area:APIAirflow's REST/HTTP APIkind:featureFeature RequestssecuritySecurity issues that must be fixed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions