Eason09053360 opened a new pull request, #74364: URL: https://github.com/apache/airflow/pull/74364
### Why `BaseAuthManager.get_user_from_token` runs on the event loop for every authenticated request, but its revocation lookup is a synchronous DB round trip. UI polling, worker heartbeats and `airflowctl` all queue behind it, and once the connection pool is saturated the loop blocks waiting for a connection, so queued requests fail one by one at `pool_timeout` (#66493). The same lookup also runs the expired-row cleanup as one unbounded `DELETE` on the request path. ### What - Run the lookup via `run_in_threadpool`, like `TeamAuthorizationMiddleware.dispatch`. - Delete at most 100 expired rows per pass; a non-blocking lock keeps the now-concurrent passes to one, and a failed pass rolls back so the following read survives on PostgreSQL. FAB's `deserialize_user` DB I/O on the loop is out of scope (its `TTLCache` is not thread-safe). #71444 edits the same line; whichever lands second needs a trivial rebase. related: #73422 (same change rebased onto main; the original was closed under the open-PR limit) --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes — Claude Code (Opus 5.5) Generated-by: Claude Code (Opus 5.5) following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
