Samin061 opened a new pull request, #73894: URL: https://github.com/apache/airflow/pull/73894
Flask-AppBuilder's security views issue the session JWT cookie through this `redirect()` helper after login, and it calls werkzeug's `set_cookie` without a `samesite` argument. werkzeug leaves SameSite unset in that case, so the FAB session cookie is the only Airflow auth cookie sent with no SameSite attribute: the Starlette-based auth managers get `SameSite=Lax` from Starlette's own default, and the keycloak middleware, the refresh-token middleware and the simple auth manager set it explicitly. On browsers that do not treat an unspecified cookie as Lax the FAB session cookie rides along on cross-site requests, which is the CSRF exposure SameSite is meant to close. I noticed it while comparing the cookie attributes across the auth managers. Setting `samesite="Lax"` here brings the cookie in line with the rest; Lax still sends it on top-level navigation, so the post-login redirect is unaffected. --- ##### Was generative AI tooling used to co-author this PR? - [x] Yes (please specify the tool below) Generated-by: Claude Code following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) --- * Read the **[Pull Request Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)** for more information. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
