omarmohsen opened a new issue, #73941:
URL: https://github.com/apache/airflow/issues/73941

   ### Under which category would you file this issue?
   
   Providers
   
   ### Apache Airflow version
   
   3.2.2
   
   ### What happened and how to reproduce it?
   
   LDAP Authentication fails with a referer host mismatch when Airflow 3 is 
exposed via HTTPRoute and the gateway listener port is different from original 
port used to access Airflow.
   1) Deploy Airflow 3 using main helm chart.
   2) Configure LDAP Authentication for Airflow 3 using apiServerConfig.
   3) Expose Airflow via HTTPRoute, and gateway listener port is different from 
the port we reach Airflow.
   4) Attempt to login, the login will fail.
   
   ### What you think should happen instead?
   
   The error returned is 'The referrer does not match the host' (HTTP code 
400). It is possible due to port mismatch between gateway and referer URL. 
Disabling XSRF on Flask level works, but it should be avoided, there is a 
workaround for the issue is to add a filter to the HTTPRoute and delete the 
X-Forwarded-Port header, however there could be a better approach, I might be 
missing something.
   
   ### Operating System
   
   Debian
   
   ### Deployment
   
   Official Apache Airflow Helm Chart
   
   ### Apache Airflow Provider(s)
   
   _No response_
   
   ### Versions of Apache Airflow Providers
   
   _No response_
   
   ### Official Helm Chart version
   
   main (development)
   
   ### Kubernetes Version
   
   1.35
   
   ### Helm Chart configuration
   
   Enable httproute with specifying gateway and hostnames
   
   ### Docker Image customizations
   
   _No response_
   
   ### Anything else?
   
   I am willing to submit a PR, if the change is helm based.
   
   ### Are you willing to submit PR?
   
   - [x] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://github.com/apache/airflow/blob/main/CODE_OF_CONDUCT.md)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to