ashb commented on PR #67878:
URL: https://github.com/apache/airflow/pull/67878#issuecomment-4600014299

   > Auth. The processor self-signs a token for [dag_processor] jwt_audience 
with the
   > deployment signing key, and the endpoints validate it via JWTBearer
   
   I am wary of giving the dag processor the ability to mint any tokens at all 
-- given it runs user code this seems like it's a huge security risk 🤔 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to