Vamsi-klu opened a new pull request, #73365:
URL: https://github.com/apache/airflow/pull/73365

   Document the complete redirect-based login lifecycle for custom FastAPI auth 
managers. The new guidance shows how to preserve and validate the original UI 
destination, verify one-time state before authenticating the user, generate the 
Airflow JWT, and attach the `_token` cookie to the final callback response 
before returning to the UI.
   
   The example uses Airflow's configured base URL, auth-manager mount prefix, 
and canonical cookie helpers. It also covers prefixed deployments, proxy-aware 
secure cookies, concurrent login attempts, provider failures, token lifetime, 
and avoiding credential or token leakage. Provider exchange and state helpers 
remain explicit placeholders so the pattern applies to OAuth, OIDC, SAML, and 
similar flows.
   
   This differs from the FAB fix in #61287, which persists a Flask session 
before redirecting. FastAPI auth managers instead need to set the Airflow JWT 
cookie on the successful final callback response.
   
   closes: #63521
   
   Checks:
   
   - `prek run rst-backticks --files 
airflow-core/docs/core-concepts/auth-manager/index.rst`
   - `prek run codespell --files 
airflow-core/docs/core-concepts/auth-manager/index.rst`
   - `breeze build-docs --package-filter apache-airflow`
   - `prek run --from-ref upstream/main --stage pre-commit`
   - `prek run --from-ref upstream/main --stage manual --skip 
compile-ui-assets-dev --skip view-skill-eval --skip run-skill-eval-codex`
   - `breeze ci selective-check --commit-ref HEAD`
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — OpenAI Codex (GPT-5)
   
   Generated-by: OpenAI Codex (GPT-5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   
   ---
   Drafted-by: OpenAI Codex (GPT-5) (no human review before posting)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to