Uh oh!
There was an error while loading. Please reload this page.
Make raw HTML descriptions configurable - #35460
Conversation
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
…-description-in-params-configurable
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
…-description-in-params-configurable
potiuk
commented
Nov 12, 2023
Looks like all checks passed :) |
potiuk
commented
Nov 12, 2023
I think the only thing we need is |
jscheffl
commented
Nov 12, 2023
@potiuk how about the one already in? --> https://github.com/apache/airflow/pull/35460/files#diff-1fa4ad17cb7d1ce8e7e5c724a04fceaac361d7cc44f4c27143359083cb4bb700 |
potiuk
commented
Nov 12, 2023
Good enough :) |
mentioned by CVE-2023-47265 |
With AIP-50 we introduced trigger forms and such trigger forms allow to provide raw HTML by DAG authors as descriptions.
During Airflow Summit there were some concerns discussed whether a DAG author would be able to inject dangerous JavaScript into the HTML and how Airflow handles this.
This PR changes the raw HTML support in Airflow in the way:
allow_html_in_dag_docsis added, which defaults to Falsecustom_html_formin trigger DAG UI is marked as deprecated for a future / better solution