Vamsi-klu commented on PR #73365:
URL: https://github.com/apache/airflow/pull/73365#issuecomment-5761149619
Thanks for catching the callback URL. You are right that `[api] base_url`
has no default. With `fallback="/"` and urlsplit, the sample handed providers a
relative `/auth/callback`, which they reject. I copied the Keycloak helper.
Prefer the configured base URL with urljoin, and fall back to
`request.url_for("callback")` when it is unset.
I also dropped the `validate_airflow_return_url` placeholder and pointed the
example at `is_safe_url` from `airflow.api_fastapi.core_api.security`. That is
the same check the core `/auth/login` route and the simple auth manager already
run.
The repeated "UI does not manage the token" line in the note is gone.
On the issue footer, I switched `closes` to `related to`. #63521 is the
Unauthorized flash during the redirect chain. This PR documents the FastAPI
cookie-on-final-callback pattern. It does not change UI or core behavior, so it
should not close that ticket. I added one sentence that names the flash so
people hitting that symptom can find the pattern.
Happy to tweak the wording if anything still reads off.
---
Drafted-by: Cursor Grok 4.6; reviewed by @Vamsi-klu before posting
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]