Eason09053360 opened a new pull request, #74364:
URL: https://github.com/apache/airflow/pull/74364

   ### Why
   
   `BaseAuthManager.get_user_from_token` runs on the event loop for every 
authenticated request, but its revocation lookup is a synchronous DB round 
trip. UI polling, worker heartbeats and `airflowctl` all queue behind it, and 
once the connection pool is saturated the loop blocks waiting for a connection, 
so queued requests fail one by one at `pool_timeout` (#66493). The same lookup 
also runs the expired-row cleanup as one unbounded `DELETE` on the request path.
   
   ### What
   
   - Run the lookup via `run_in_threadpool`, like 
`TeamAuthorizationMiddleware.dispatch`.
   - Delete at most 100 expired rows per pass; a non-blocking lock keeps the 
now-concurrent passes to one, and a failed pass rolls back so the following 
read survives on PostgreSQL.
   
   FAB's `deserialize_user` DB I/O on the loop is out of scope (its `TTLCache` 
is not thread-safe). #71444 edits the same line; whichever lands second needs a 
trivial rebase.
   
   related: #73422 (same change rebased onto main; the original was closed 
under the open-PR limit)
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code (Opus 5.5)
   
   Generated-by: Claude Code (Opus 5.5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to