Alwaysgaurav1 opened a new pull request, #73608: URL: https://github.com/apache/airflow/pull/73608
### Description Closes: #68382 This PR addresses #68382 by validating that connection port numbers fall within the standard TCP/UDP port range (`1 <= port <= 65535`) across all write/input paths in Apache Airflow (`airflow-core`, `task-sdk`, `api_fastapi`, and CLI). #### Key Design Decisions: 1. **Valid Range (`1 <= port <= 65535`)**: Port `0` is strictly rejected as invalid for establishing external connections; `None` represents an unconfigured or default port. 2. **Write-Path Enforced, Read-Path Safe**: Validation is enforced on constructors, API request bodies, and CLI inputs. Response models (`ConnectionResponse`) and DB `@reconstructor` hooks remain unconstrained so that reading pre-existing database records with invalid or legacy ports does not cause failures for users. 3. **Task SDK**: Port validation is enforced via attrs validator on `Connection` and handled in `Connection.from_json()`. 4. **CLI**: `ARG_CONN_PORT` is updated to `type=int` with `(1-65535)` help text so argparse enforces integer format early. 5. **FastAPI**: `ConnectionBody.port` enforces `ge=1, le=65535` across connection creation, partial updates, tests, and bulk operations. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
