Vamsi-klu opened a new pull request, #73365: URL: https://github.com/apache/airflow/pull/73365
Document the complete redirect-based login lifecycle for custom FastAPI auth managers. The new guidance shows how to preserve and validate the original UI destination, verify one-time state before authenticating the user, generate the Airflow JWT, and attach the `_token` cookie to the final callback response before returning to the UI. The example uses Airflow's configured base URL, auth-manager mount prefix, and canonical cookie helpers. It also covers prefixed deployments, proxy-aware secure cookies, concurrent login attempts, provider failures, token lifetime, and avoiding credential or token leakage. Provider exchange and state helpers remain explicit placeholders so the pattern applies to OAuth, OIDC, SAML, and similar flows. This differs from the FAB fix in #61287, which persists a Flask session before redirecting. FastAPI auth managers instead need to set the Airflow JWT cookie on the successful final callback response. closes: #63521 Checks: - `prek run rst-backticks --files airflow-core/docs/core-concepts/auth-manager/index.rst` - `prek run codespell --files airflow-core/docs/core-concepts/auth-manager/index.rst` - `breeze build-docs --package-filter apache-airflow` - `prek run --from-ref upstream/main --stage pre-commit` - `prek run --from-ref upstream/main --stage manual --skip compile-ui-assets-dev --skip view-skill-eval --skip run-skill-eval-codex` - `breeze ci selective-check --commit-ref HEAD` --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes — OpenAI Codex (GPT-5) Generated-by: OpenAI Codex (GPT-5) following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) --- Drafted-by: OpenAI Codex (GPT-5) (no human review before posting) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
