potiuk opened a new pull request, #73695: URL: https://github.com/apache/airflow/pull/73695
When the Keycloak access token had expired, KeycloakJWTMiddleware refreshed the user before the endpoint ran and, after it returned, always set a newly signed Airflow JWT on the response. On /auth/logout the endpoint revokes the JWT the request came with, so the middleware replaced the revoked token with a fresh, unrevoked one and the session stayed usable after logout. After the endpoint returns, the middleware now checks that the JWT sent with the request is still accepted before issuing a replacement. If it has been revoked, no new JWT is issued and the Airflow and Keycloak token cookies are cleared instead. A JWT that merely expired while the request was handled is still replaced as before. --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes — Claude Code (Claude Opus 5) Generated-by: Claude Opus 5 following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
