fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: Add missing security settings for session cookie - #53542

Merged
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie
Aug 1, 2025
Merged

fix: Add missing security settings for session cookie#53542
vincbeck merged 1 commit into
apache:mainfrom
LipuFei:fix/session_cookie

Conversation

@LipuFei

@LipuFeiLipuFei commented Jul 19, 2025

Copy link
Copy Markdown
Contributor

Add the following security-related session cookie settings that was missing:

  • SESSION_COOKIE_HTTPONLY = True
  • SESSION_COOKIE_SECURE comes from config [fab] COOKIE_SECURE
  • SESSION_COOKIE_SAMESITE comes from config [fab] COOKIE_SAMESITE
  • config [webserver] COOKIE_SECURE is renamed to [fab] COOKIE_SECURE
  • config [webserver] COOKIE_SAMESITE is renamed to [fab] COOKIE_SAMESITE

We may want to change the config location because this is now in api-server in 3.0?

@LipuFei
LipuFei requested a review from vincbeck as a code ownerJuly 19, 2025 16:04
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 4 times, most recently from 1f8602d to 5c4742aCompareJuly 19, 2025 19:25
@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

@vincbeck

Copy link
Copy Markdown
Contributor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

@LipuFei

Copy link
Copy Markdown
ContributorAuthor

We marked these configs as deleted in airflow-ctl/src/airflowctl/ctl/commands/config_command.py. If we want to use them back, we should them remove them from airflow-ctl/src/airflowctl/ctl/commands/config_command.py as well.

Hi @vincelevey , I don't necessarily need these options back, but I found that with self-hosting, the api-server doesn't have these options on by default. I can see from Firefox that my session cookie is not HTTP-only, and not secure, etc.

Perhaps you know a better way to have them configured in api-server in 3.0?

I currently just add these 3 options in the api-server config python file via the Helm chart values, and it works. I think it would be great if these options can be set more transparently.

You are using these config so you need them back and I think this is okay. You are using these configs conf.getboolean("webserver", "COOKIE_SECURE") and conf.get("webserver", "COOKIE_SAMESITE"). I think the right approach would be to move these config to Fab provider because they are specific to Fab. Once done you would need to update airflow-core/src/airflow/cli/commands/config_command.py and airflow-ctl/src/airflowctl/ctl/commands/config_command.py to no longer mark them as deleted but moved from webserver to fab. This PR is a good example on how to do that.

Thank you. I will check that PR and update my changes.

@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch 2 times, most recently from f358a37 to b28ee8fCompareJuly 31, 2025 22:33
@LipuFei
LipuFeiforce-pushed the fix/session_cookie branch from b28ee8f to af273a2CompareAugust 1, 2025 09:01

@vin100bkvin100bk left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeckvincbeck left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking the time to update the PR :) Much appreciated

@vincbeck
vincbeck merged commit fa09189 into apache:mainAug 1, 2025
72 checks passed
@LipuFei
LipuFei deleted the fix/session_cookie branch August 1, 2025 14:34
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
fweilun pushed a commit to fweilun/airflow that referenced this pull request Aug 11, 2025
@snowsky

snowsky commented Dec 16, 2025

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

Update: a quick question, not sure if this issue is related, #47878, which will be released in 3.2.0.

@vincbeck

Copy link
Copy Markdown
Contributor

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

@snowsky

Copy link
Copy Markdown

Will this fix be included in the next release? Thanks!

It is mostly a provider change so this is already released in the latest fab provider version

Is this env var still valid AIRFLOW__WEBSERVER__COOKIE_SECURE? I saw it was introduced in version 1.3 but didn't find it in version 3 docs.

@vincbeck

Copy link
Copy Markdown
Contributor

It is now AIRFLOW__FAB__COOKIE_SECURE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@LipuFei@vincbeck@snowsky@vin100bk