New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Improve diagnostics message when users have secret_key misconfigured #17410
Merged
potiuk
merged 2 commits into
apache:main
from
potiuk:help-users-when-they-get-403-on-log-retrieval
Aug 4, 2021
Merged
Improve diagnostics message when users have secret_key misconfigured #17410
potiuk
merged 2 commits into
apache:main
from
potiuk:help-users-when-they-get-403-on-log-retrieval
Aug 4, 2021
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
potiuk
force-pushed
the
help-users-when-they-get-403-on-log-retrieval
branch
from
August 4, 2021 11:24
17900a9
to
1d095ce
Compare
ashb
reviewed
Aug 4, 2021
potiuk
force-pushed
the
help-users-when-they-get-403-on-log-retrieval
branch
from
August 4, 2021 11:25
1d095ce
to
d9d2768
Compare
Recently fixed log open-access vulnerability have caused quite a lot of questions and issues from the affected users who did not have webserver/secret_key configured for their workers (effectively leading to random value for those keys for workers) This PR explicitly explains the possible reason for the problem and encourages the user to configure their webserver's secret_key in both - workers and webserver. Related to: apache#17251 and a number of similar slack discussions.
potiuk
force-pushed
the
help-users-when-they-get-403-on-log-retrieval
branch
from
August 4, 2021 11:26
d9d2768
to
d5d9413
Compare
ashb
reviewed
Aug 4, 2021
ashb
approved these changes
Aug 4, 2021
The PR most likely needs to run full matrix of tests because it modifies parts of the core of Airflow. However, committers might decide to merge it quickly and take the risk. If they don't merge it quickly - please rebase it to the latest main at your convenience, or amend the last commit of the PR, and push it with --force-with-lease. |
github-actions
bot
added
the
full tests needed
We need to run full set of tests for this PR to merge
label
Aug 4, 2021
Co-authored-by: Ash Berlin-Taylor <ash_github@firemirror.com>
potiuk
added a commit
to potiuk/airflow
that referenced
this pull request
Aug 5, 2021
…pache#17410) * Improve diagnostics message when users have secret_key misconfigured Recently fixed log open-access vulnerability have caused quite a lot of questions and issues from the affected users who did not have webserver/secret_key configured for their workers (effectively leading to random value for those keys for workers) This PR explicitly explains the possible reason for the problem and encourages the user to configure their webserver's secret_key in both - workers and webserver. Related to: apache#17251 and a number of similar slack discussions. (cherry picked from commit 2321020)
jhtimmins
pushed a commit
that referenced
this pull request
Aug 9, 2021
…17410) * Improve diagnostics message when users have secret_key misconfigured Recently fixed log open-access vulnerability have caused quite a lot of questions and issues from the affected users who did not have webserver/secret_key configured for their workers (effectively leading to random value for those keys for workers) This PR explicitly explains the possible reason for the problem and encourages the user to configure their webserver's secret_key in both - workers and webserver. Related to: #17251 and a number of similar slack discussions. (cherry picked from commit 2321020)
kaxil
pushed a commit
that referenced
this pull request
Aug 17, 2021
…17410) * Improve diagnostics message when users have secret_key misconfigured Recently fixed log open-access vulnerability have caused quite a lot of questions and issues from the affected users who did not have webserver/secret_key configured for their workers (effectively leading to random value for those keys for workers) This PR explicitly explains the possible reason for the problem and encourages the user to configure their webserver's secret_key in both - workers and webserver. Related to: #17251 and a number of similar slack discussions. (cherry picked from commit 2321020)
jhtimmins
pushed a commit
that referenced
this pull request
Aug 17, 2021
…17410) * Improve diagnostics message when users have secret_key misconfigured Recently fixed log open-access vulnerability have caused quite a lot of questions and issues from the affected users who did not have webserver/secret_key configured for their workers (effectively leading to random value for those keys for workers) This PR explicitly explains the possible reason for the problem and encourages the user to configure their webserver's secret_key in both - workers and webserver. Related to: #17251 and a number of similar slack discussions. (cherry picked from commit 2321020)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Recently fixed log open-access vulnerability have caused
quite a lot of questions and issues from the affected users who
did not have webserver/secret_key configured for their workers
(effectively leading to random value for those keys for workers)
This PR explicitly explains the possible reason for the problem and
encourages the user to configure their webserver's secret_key
in both - workers and webserver.
Related to: #17251 and a number of similar slack discussions.
^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code change, Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in UPDATING.md.