Skip to content

Do not get logout_callback_url from request in keycloak auth manager#62795

Merged
vincbeck merged 1 commit intoapache:mainfrom
aws-mwaa:vincbeck/security_keycloak
Mar 3, 2026
Merged

Do not get logout_callback_url from request in keycloak auth manager#62795
vincbeck merged 1 commit intoapache:mainfrom
aws-mwaa:vincbeck/security_keycloak

Conversation

@vincbeck
Copy link
Contributor

@vincbeck vincbeck commented Mar 3, 2026

Getting logout_callback_url from the request is a security risk. Instead, I set it using [api] base_url.


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@vincbeck vincbeck merged commit 7a19002 into apache:main Mar 3, 2026
161 of 162 checks passed
@vincbeck vincbeck deleted the vincbeck/security_keycloak branch March 3, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants