Skip to content

Mask Connection password in Task SDK - #71306

Open
roshanprabu wants to merge 1 commit into
apache:mainfrom
roshanprabu:fix-azure-conn-secret-masking
Open

Mask Connection password in Task SDK#71306
roshanprabu wants to merge 1 commit into
apache:mainfrom
roshanprabu:fix-azure-conn-secret-masking

Conversation

@roshanprabu

Copy link
Copy Markdown

Summary

airflow.sdk.definitions.connection.Connection (the Task SDK connection model used inside a running task in Airflow 3.x) masks extra fields via mask_secret(), but never masked the top-level password field, unlike the core ORM Connection. This meant secrets such as an Azure service principal secret (which maps to Connection.password) leaked into task logs unmasked whenever the connection was resolved through the Task SDK — e.g. when sourced from an AIRFLOW_CONN_* environment variable URI.

This adds the same mask_secret(self.password) / mask_secret(quote(self.password)) calls that the core Connection class already performs, covering both the direct-kwargs constructor and the from_uri path.

Closes: #38144

Test plan

  • Added test_password_is_masked in task-sdk/tests/task_sdk/definitions/test_connection.py, covering both the kwargs constructor and from_uri.
  • Verified against a pre-fix checkout that the new assertions fail without the change (masking returns False) and pass with it.
  • ruff check and ruff format --check pass on the changed files.

airflow.sdk.definitions.connection.Connection masked extra fields via
mask_secret() but never masked the top-level password field, unlike the
core ORM Connection. This meant secrets such as an Azure service
principal secret (mapped to Connection.password) leaked into task logs
unmasked whenever the connection was resolved through the Task SDK, e.g.
when sourced from an AIRFLOW_CONN_* environment variable URI.

Closes: apache#38144
@boring-cyborg

boring-cyborg Bot commented Aug 7, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Microsoft Azure Connection: Service principal secret does not get masked when providing connection via URI environment variable

1 participant