-
Notifications
You must be signed in to change notification settings - Fork 16.5k
Open
Labels
area:APIAirflow's REST/HTTP APIAirflow's REST/HTTP APIkind:featureFeature RequestsFeature RequestssecuritySecurity issues that must be fixedSecurity issues that must be fixed
Description
Description
Enhance security by eliminating regexp usage in any of the requests. Even if someone is trying to send regexp in str fields, we should return a proper error message that regexp isn't allowed.
https://fastapi.tiangolo.com/tutorial/middleware/#create-a-middleware
Use case/motivation
https://lists.apache.org/thread/xtzdp4dx8s6dds4xdp9kdpohns9lvpst
Related issues
Followup: #46971
Are you willing to submit a PR?
- Yes I am willing to submit a PR!
Code of Conduct
- I agree to follow this project's Code of Conduct
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area:APIAirflow's REST/HTTP APIAirflow's REST/HTTP APIkind:featureFeature RequestsFeature RequestssecuritySecurity issues that must be fixedSecurity issues that must be fixed