rjgoyln commented on code in PR #64105:
URL: https://github.com/apache/airflow/pull/64105#discussion_r4062837909


##########
providers/git/src/airflow/providers/git/bundles/git.py:
##########
@@ -317,6 +322,47 @@ def _clone_bare_repo_if_required(self) -> None:
                 shutil.rmtree(self.bare_repo_path)
             raise
 
+    def _sync_bare_repo_remote_url(self) -> None:
+        """
+        Re-point the bare repo's origin at the current repo url.
+
+        Called standalone from the ``_initialize`` fast paths that skip 
cloning and never
+        reach ``_clone_bare_repo_if_required``, so a bundle that takes one 
would otherwise
+        keep a credentialed origin url in ``bare/config`` forever. This is 
best-effort: a
+        bundle that can still be served from disk must not fail to initialize 
because its
+        bare repo is unreadable.
+        """
+        try:
+            if not self.bare_repo_path.exists():
+                return
+            bare_repo = Repo(self.bare_repo_path)
+            try:
+                self._rewrite_bare_repo_origin(bare_repo)
+            finally:
+                bare_repo.close()
+        except Exception as e:
+            # Deliberately broad: opening the repo raises anything from 
``configparser`` on a
+            # truncated config to ``GitError`` on an unsafe remote url, and 
the fast paths this
+            # runs ahead of never needed the bare repo at all.
+            self._log.warning(
+                "Could not rewrite the bare repository origin, a credential 
may remain in "
+                "cleartext in the bundle's bare/config",
+                bare_repo_path=self.bare_repo_path,
+                exc=e,
+            )
+
+    def _rewrite_bare_repo_origin(self, bare_repo: Repo) -> None:
+        if "origin" not in bare_repo.remotes:
+            return
+        origin = bare_repo.remotes.origin
+        repo_url = str(self.repo_url)
+        # Bundles cloned before credentials moved to a credential helper 
embedded ``user:token``
+        # here, so the token sits in cleartext in ``<bundle>/bare/config`` 
where any Dag author
+        # on the Dag processor can read it. Rewriting origin is what removes 
it from those bundles.
+        if origin.url != repo_url:
+            self._log.info("Updating bare repository remote url", 
bare_repo_path=self.bare_repo_path)
+            origin.set_url(repo_url)

Review Comment:
   Fixed in `1ba9bac33f` by checking whether the existing `origin` contains 
credentials, preserving Git's resolved local path. Added a regression test for 
relative source paths.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to