potiuk opened a new pull request, #73695:
URL: https://github.com/apache/airflow/pull/73695

   When the Keycloak access token had expired, KeycloakJWTMiddleware refreshed
   the user before the endpoint ran and, after it returned, always set a newly
   signed Airflow JWT on the response. On /auth/logout the endpoint revokes the
   JWT the request came with, so the middleware replaced the revoked token with
   a fresh, unrevoked one and the session stayed usable after logout.
   
   After the endpoint returns, the middleware now checks that the JWT sent with
   the request is still accepted before issuing a replacement. If it has been
   revoked, no new JWT is issued and the Airflow and Keycloak token cookies are
   cleared instead. A JWT that merely expired while the request was handled is
   still replaced as before.
   
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code (Claude Opus 5)
   
   Generated-by: Claude Opus 5 following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to