Eason09053360 opened a new pull request, #73465:
URL: https://github.com/apache/airflow/pull/73465

   ## Why
   
   `GET /ui/grid/ti_summaries/{dag_id}` opens its own DB session and 
deserializes the serialized Dag once per `run_id`, and the parameter had no 
upper bound. Any authenticated user can hand-craft a URL with an arbitrary 
number of `run_ids` and hold the streaming response open while the server works 
through that many sessions and deserializations, occupying connections from the 
pool the whole API server shares. The page itself can never do this: 
`/ui/grid/runs/{dag_id}` already clamps its limit to `[api] maximum_page_limit`.
   
   ## What
   
   - Cap `run_ids` at `[api] maximum_page_limit` in 
`airflow-core/src/airflow/api_fastapi/core_api/routes/ui/grid.py`, mirroring 
the `dag_ids` cap on `routes/ui/dags.py`.
   - Regenerated `_private_ui.yaml` (adds `maxItems`); the generated TS client 
is unchanged.
   - New test asserts 422 past the limit; it fails without the cap.
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code (Opus 5)
   
   Generated-by: Claude Code (Opus 5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to