rjgoyln commented on code in PR #64105:
URL: https://github.com/apache/airflow/pull/64105#discussion_r4062837909
##########
providers/git/src/airflow/providers/git/bundles/git.py:
##########
@@ -317,6 +322,47 @@ def _clone_bare_repo_if_required(self) -> None:
shutil.rmtree(self.bare_repo_path)
raise
+ def _sync_bare_repo_remote_url(self) -> None:
+ """
+ Re-point the bare repo's origin at the current repo url.
+
+ Called standalone from the ``_initialize`` fast paths that skip
cloning and never
+ reach ``_clone_bare_repo_if_required``, so a bundle that takes one
would otherwise
+ keep a credentialed origin url in ``bare/config`` forever. This is
best-effort: a
+ bundle that can still be served from disk must not fail to initialize
because its
+ bare repo is unreadable.
+ """
+ try:
+ if not self.bare_repo_path.exists():
+ return
+ bare_repo = Repo(self.bare_repo_path)
+ try:
+ self._rewrite_bare_repo_origin(bare_repo)
+ finally:
+ bare_repo.close()
+ except Exception as e:
+ # Deliberately broad: opening the repo raises anything from
``configparser`` on a
+ # truncated config to ``GitError`` on an unsafe remote url, and
the fast paths this
+ # runs ahead of never needed the bare repo at all.
+ self._log.warning(
+ "Could not rewrite the bare repository origin, a credential
may remain in "
+ "cleartext in the bundle's bare/config",
+ bare_repo_path=self.bare_repo_path,
+ exc=e,
+ )
+
+ def _rewrite_bare_repo_origin(self, bare_repo: Repo) -> None:
+ if "origin" not in bare_repo.remotes:
+ return
+ origin = bare_repo.remotes.origin
+ repo_url = str(self.repo_url)
+ # Bundles cloned before credentials moved to a credential helper
embedded ``user:token``
+ # here, so the token sits in cleartext in ``<bundle>/bare/config``
where any Dag author
+ # on the Dag processor can read it. Rewriting origin is what removes
it from those bundles.
+ if origin.url != repo_url:
+ self._log.info("Updating bare repository remote url",
bare_repo_path=self.bare_repo_path)
+ origin.set_url(repo_url)
Review Comment:
Fixed in `1ba9bac33f` by checking whether the existing `origin` contains
credentials, preserving Git's resolved local path. Added a regression test for
relative source paths.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]