Eason09053360 opened a new pull request, #73465:
URL: https://github.com/apache/airflow/pull/73465
## Why
`GET /ui/grid/ti_summaries/{dag_id}` opens its own DB session and
deserializes the serialized Dag once per `run_id`, and the parameter had no
upper bound. Any authenticated user can hand-craft a URL with an arbitrary
number of `run_ids` and hold the streaming response open while the server works
through that many sessions and deserializations, occupying connections from the
pool the whole API server shares. The page itself can never do this:
`/ui/grid/runs/{dag_id}` already clamps its limit to `[api] maximum_page_limit`.
## What
- Cap `run_ids` at `[api] maximum_page_limit` in
`airflow-core/src/airflow/api_fastapi/core_api/routes/ui/grid.py`, mirroring
the `dag_ids` cap on `routes/ui/dags.py`.
- Regenerated `_private_ui.yaml` (adds `maxItems`); the generated TS client
is unchanged.
- New test asserts 422 past the limit; it fails without the cap.
---
##### Was generative AI tooling used to co-author this PR?
- [X] Yes — Claude Code (Opus 5)
Generated-by: Claude Code (Opus 5) following [the
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]