potiuk opened a new pull request, #73852: URL: https://github.com/apache/airflow/pull/73852
Follow-up to #70681, fixing issues found in a post-merge review. - **Sync hook had stopped checking anything.** `check-secrets-search-path-sync` only reads string literals, but #70681 changed both lists to reference constants in `airflow_shared.configuration.secrets_backends`. The hook extracted `[]` from both files and always passed. The server default search path is now defined once in the shared module (`SERVER_DEFAULT_SECRETS_SEARCH_PATH`), core and the Task SDK both derive from it, and the hook is removed. - **`version_added`** for `[secrets] backends_order` and `[workers] backends_order` is corrected from `3.3.0` (already released without these options) to `3.4.0`. - **Docs example stopped Airflow from starting.** The example blocks showed `backends_order =` with no value, which the required-backend check rejects when `airflow.configuration` is imported. The examples now show the defaults. The docs now also say that an empty value is rejected, and that `custom` must be listed when a custom backend is configured. Option references use the `[section] option` notation. - **UI:** the "Secret backends order" card on the Variables page is now shown only to users who can access the Config page, matching the permission the endpoint requires. Previously, users without that access always got a 403 when opening it. - **Newsfragment** changed from `significant` to `feature` (the defaults keep the existing behaviour), and it no longer mentions the private `/ui` endpoint. Tests run locally: - `airflow-core/tests/unit/always/test_secrets.py` and `airflow-core/tests/unit/api_fastapi/core_api/routes/ui/test_config.py`: 41 passed - `task-sdk/tests/task_sdk/execution_time/test_secrets.py` and `test_context.py`: 219 passed - `src/pages/Variables/` vitest: 7 passed. The new `BackendsOrderCard.test.tsx` fails without the gating change. - ESLint and Prettier are clean on the changed UI files, and ruff is clean on the changed Python files. cc @lubimow-xwf @shahar1 --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes (please specify the tool below) Generated-by: Claude Code (Opus 5.5) following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
