Samin061 opened a new pull request, #73894:
URL: https://github.com/apache/airflow/pull/73894

   Flask-AppBuilder's security views issue the session JWT cookie through this 
`redirect()` helper after login, and it calls werkzeug's `set_cookie` without a 
`samesite` argument. werkzeug leaves SameSite unset in that case, so the FAB 
session cookie is the only Airflow auth cookie sent with no SameSite attribute: 
the Starlette-based auth managers get `SameSite=Lax` from Starlette's own 
default, and the keycloak middleware, the refresh-token middleware and the 
simple auth manager set it explicitly. On browsers that do not treat an 
unspecified cookie as Lax the FAB session cookie rides along on cross-site 
requests, which is the CSRF exposure SameSite is meant to close. I noticed it 
while comparing the cookie attributes across the auth managers. Setting 
`samesite="Lax"` here brings the cookie in line with the rest; Lax still sends 
it on top-level navigation, so the post-login redirect is unaffected.
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [x] Yes (please specify the tool below)
   
   Generated-by: Claude Code following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   
   ---
   
   * Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
 for more information.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to