potiuk opened a new pull request, #73789:
URL: https://github.com/apache/airflow/pull/73789
In multi-team mode with team-scoped paths, the Vault and Akeyless secrets
backends build a team's secret names under the same base path that a lookup
with no team resolves in. A connection or variable id containing the path
separator, looked up with no team, could therefore name a team's secret:
`team1/db_password` resolved `{base_path}/team1/db_password`.
Such ids are now refused for a caller with no team, the same way both
backends already refuse them for a caller with a team:
- **Vault** — refused when the id's path part (below the mount point)
contains `/`, in multi-team mode with `use_team_secrets_path` enabled.
- **Akeyless** — refused under the same conditions unless
`global_secrets_path` is set, which gives secrets used outside any team a
namespace of their own; nested ids keep working there.
The Amazon, Azure and Yandex backends already refuse ids containing their
team separator for every caller, so they need no change. Outside multi-team
mode, or with `use_team_secrets_path=False`, nothing changes. Both provider
changelogs carry a note, since nested ids looked up with no team stop resolving
in the affected configuration.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]