Skip to content

[AIRFLOW-6349] - secure api and cookie by default#6907

Closed
tooptoop4 wants to merge 1 commit intoapache:masterfrom
tooptoop4:AIRFLOW-6349
Closed

[AIRFLOW-6349] - secure api and cookie by default#6907
tooptoop4 wants to merge 1 commit intoapache:masterfrom
tooptoop4:AIRFLOW-6349

Conversation

@tooptoop4
Copy link
Contributor

@tooptoop4 tooptoop4 commented Dec 26, 2019

AIRFLOW-6349

Make sure you have checked all steps below.

Jira

Description

  • Here are some details about my PR, including screenshots of any UI changes:

Tests

  • My PR adds the following unit tests OR does not need testing for this extremely good reason:

Commits

  • My commits all reference Jira issues in their subject lines, and I have squashed multiple commits if they address the same issue. In addition, my commits follow the guidelines from "How to write a good git commit message":
    1. Subject is separated from body by a blank line
    2. Subject is limited to 50 characters (not including Jira issue reference)
    3. Subject does not end with a period
    4. Subject uses the imperative mood ("add", not "adding")
    5. Body wraps at 72 characters
    6. Body explains "what" and "why", not "how"

Documentation

  • In case of new functionality, my PR adds documentation that describes how to use it.
    • All the public functions and the classes in the PR contain docstrings that explain what it does
    • If you implement backwards incompatible changes, please leave a note in the Updating.md so we can assign it to a appropriate release

@tooptoop4 tooptoop4 changed the title AIRFLOW-6349 AIRFLOW-6349 - secure api and cookie by default Dec 26, 2019
@tooptoop4 tooptoop4 changed the title AIRFLOW-6349 - secure api and cookie by default [AIRFLOW-6349] - secure api and cookie by default Dec 26, 2019
[api]
# How to authenticate users of the API
auth_backend = airflow.api.auth.backend.default
auth_backend = airflow.api.auth.backend.deny_all
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add note in UPDATING.MD? Some may install AIRFLOW automatically and may be surprised that the default value has changed. I also think that he should change the name of package `airflow.api.auth.backend.deny_all to a different one to better describe the content.
I also noticed that another person(me) is already working on it.
https://github.com/apache/airflow/pull/6625/files

@tooptoop4 tooptoop4 closed this Jan 2, 2020
@tooptoop4
Copy link
Contributor Author

closing as dupe of https://github.com/apache/airflow/pull/6625/files

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments