Alwaysgaurav1 opened a new pull request, #73608:
URL: https://github.com/apache/airflow/pull/73608

   
   
   ### Description
   
   Closes: #68382
   
   This PR addresses #68382 by validating that connection port numbers fall 
within the standard TCP/UDP port range (`1 <= port <= 65535`) across all 
write/input paths in Apache Airflow (`airflow-core`, `task-sdk`, `api_fastapi`, 
and CLI).
   
   #### Key Design Decisions:
   1. **Valid Range (`1 <= port <= 65535`)**: Port `0` is strictly rejected as 
invalid for establishing external connections; `None` represents an 
unconfigured or default port.
   2. **Write-Path Enforced, Read-Path Safe**: Validation is enforced on 
constructors, API request bodies, and CLI inputs. Response models 
(`ConnectionResponse`) and DB `@reconstructor` hooks remain unconstrained so 
that reading pre-existing database records with invalid or legacy ports does 
not cause failures for users.
   3. **Task SDK**: Port validation is enforced via attrs validator on 
`Connection` and handled in `Connection.from_json()`.
   4. **CLI**: `ARG_CONN_PORT` is updated to `type=int` with `(1-65535)` help 
text so argparse enforces integer format early.
   5. **FastAPI**: `ConnectionBody.port` enforces `ge=1, le=65535` across 
connection creation, partial updates, tests, and bulk operations.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to