potiuk opened a new pull request, #73789:
URL: https://github.com/apache/airflow/pull/73789

   In multi-team mode with team-scoped paths, the Vault and Akeyless secrets 
backends build a team's secret names under the same base path that a lookup 
with no team resolves in. A connection or variable id containing the path 
separator, looked up with no team, could therefore name a team's secret: 
`team1/db_password` resolved `{base_path}/team1/db_password`.
   
   Such ids are now refused for a caller with no team, the same way both 
backends already refuse them for a caller with a team:
   
   - **Vault** — refused when the id's path part (below the mount point) 
contains `/`, in multi-team mode with `use_team_secrets_path` enabled.
   - **Akeyless** — refused under the same conditions unless 
`global_secrets_path` is set, which gives secrets used outside any team a 
namespace of their own; nested ids keep working there.
   
   The Amazon, Azure and Yandex backends already refuse ids containing their 
team separator for every caller, so they need no change. Outside multi-team 
mode, or with `use_team_secrets_path=False`, nothing changes. Both provider 
changelogs carry a note, since nested ids looked up with no team stop resolving 
in the affected configuration.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to