mik-laj commented on a change in pull request #18557:
URL: https://github.com/apache/airflow/pull/18557#discussion_r745090199



##########
File path: airflow/www/views.py
##########
@@ -702,6 +702,22 @@ def _iter_parsed_moved_data_table_names():
                 # Second segment is a version marker that we don't need to 
show.
                 yield segments[2], table_name
 
+        warn_deployment_query = session.query(Log).filter(Log.event == 
"robots").count()
+        if (
+            permissions.ACTION_CAN_ACCESS_MENU,
+            permissions.RESOURCE_ADMIN_MENU,
+        ) in user_permissions and warn_deployment_query > 0:
+            flash(
+                Markup(
+                    'Recent requests have been made to /robots.txt. '
+                    'This indicates that this deployment may be accessible to 
the public internet. '
+                    'This warning can be disabled by setting 
webserver.warn_deployment_exposure=False in '
+                    'airflow.cfg. Read more about web deployment security <a 
href='
+                    
'"https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html";>here</a>'

Review comment:
       In one sentence, we are talking about a configuration option, and then 
we link to a documentation that does not contain a description of that option.




-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to