Vamsi-klu commented on PR #73365:
URL: https://github.com/apache/airflow/pull/73365#issuecomment-5761149619

   Thanks for catching the callback URL. You are right that `[api] base_url` 
has no default. With `fallback="/"` and urlsplit, the sample handed providers a 
relative `/auth/callback`, which they reject. I copied the Keycloak helper. 
Prefer the configured base URL with urljoin, and fall back to 
`request.url_for("callback")` when it is unset.
   
   I also dropped the `validate_airflow_return_url` placeholder and pointed the 
example at `is_safe_url` from `airflow.api_fastapi.core_api.security`. That is 
the same check the core `/auth/login` route and the simple auth manager already 
run.
   
   The repeated "UI does not manage the token" line in the note is gone.
   
   On the issue footer, I switched `closes` to `related to`. #63521 is the 
Unauthorized flash during the redirect chain. This PR documents the FastAPI 
cookie-on-final-callback pattern. It does not change UI or core behavior, so it 
should not close that ticket. I added one sentence that names the flash so 
people hitting that symptom can find the pattern.
   
   Happy to tweak the wording if anything still reads off.
   
   ---
   Drafted-by: Cursor Grok 4.6; reviewed by @Vamsi-klu before posting


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to