This is an automated email from the ASF dual-hosted git repository.
vincbeck pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/main by this push:
new d0b8476825d Set `SameSite` on the fab auth manager session cookie
(#73894)
d0b8476825d is described below
commit d0b8476825d986b6ffe1235e831fff36abd6bad2
Author: Samina <[email protected]>
AuthorDate: Tue Sep 29 20:02:22 2026 +0530
Set `SameSite` on the fab auth manager session cookie (#73894)
---
.../fab/src/airflow/providers/fab/www/views.py | 6 ++++--
providers/fab/tests/unit/fab/www/test_views.py | 21 ++++++++++++++++++++-
2 files changed, 24 insertions(+), 3 deletions(-)
diff --git a/providers/fab/src/airflow/providers/fab/www/views.py
b/providers/fab/src/airflow/providers/fab/www/views.py
index f89517846ef..a0b0f834d1f 100644
--- a/providers/fab/src/airflow/providers/fab/www/views.py
+++ b/providers/fab/src/airflow/providers/fab/www/views.py
@@ -146,9 +146,11 @@ def redirect(*args, **kwargs):
# See https://github.com/apache/airflow/pull/55506
cookie_path = get_cookie_path()
if AIRFLOW_V_3_1_1_PLUS:
- response.set_cookie(COOKIE_NAME_JWT_TOKEN, token,
path=cookie_path, secure=secure, httponly=True)
+ response.set_cookie(
+ COOKIE_NAME_JWT_TOKEN, token, path=cookie_path, secure=secure,
httponly=True, samesite="Lax"
+ )
else:
- response.set_cookie(COOKIE_NAME_JWT_TOKEN, token,
path=cookie_path, secure=secure)
+ response.set_cookie(COOKIE_NAME_JWT_TOKEN, token,
path=cookie_path, secure=secure, samesite="Lax")
return response
return flask_redirect(*args, **kwargs)
diff --git a/providers/fab/tests/unit/fab/www/test_views.py
b/providers/fab/tests/unit/fab/www/test_views.py
index e859121203a..d9bc7dce22c 100644
--- a/providers/fab/tests/unit/fab/www/test_views.py
+++ b/providers/fab/tests/unit/fab/www/test_views.py
@@ -18,10 +18,12 @@
from __future__ import annotations
import time
+from unittest import mock
import pytest
-from flask import Flask, session as builtin_flask_session
+from flask import Flask, g, session as builtin_flask_session
+from airflow.providers.fab.www import views
from airflow.providers.fab.www.extensions.init_session import
SESSION_LOGIN_TIME_KEY
from airflow.providers.fab.www.views import get_token_expiration_seconds
@@ -65,3 +67,20 @@ def
test_token_expiration_is_uncapped_for_a_session_without_a_login_stamp(app):
}
with app.test_request_context(), conf_vars(overrides):
assert get_token_expiration_seconds() == JWT_EXPIRATION_TIME
+
+
+def test_redirect_sets_samesite_on_token_cookie(app):
+ with app.test_request_context():
+ user = mock.Mock()
+ user.is_authenticated = True
+ g.user = user
+ with (
+ mock.patch("airflow.providers.fab.www.views.get_auth_manager") as
mock_get_auth_manager,
+
mock.patch("airflow.providers.fab.www.views.get_token_expiration_seconds",
return_value=3600),
+ mock.patch("airflow.providers.fab.www.views.get_cookie_path",
return_value="/"),
+ ):
+ mock_get_auth_manager.return_value.generate_jwt.return_value =
"token"
+ response = views.redirect("/home")
+ set_cookie = response.headers.get("Set-Cookie")
+ assert set_cookie is not None
+ assert "samesite=lax" in set_cookie.lower()