This is an automated email from the ASF dual-hosted git repository.

vincbeck pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/main by this push:
     new d0b8476825d Set `SameSite` on the fab auth manager session cookie 
(#73894)
d0b8476825d is described below

commit d0b8476825d986b6ffe1235e831fff36abd6bad2
Author: Samina <[email protected]>
AuthorDate: Tue Sep 29 20:02:22 2026 +0530

    Set `SameSite` on the fab auth manager session cookie (#73894)
---
 .../fab/src/airflow/providers/fab/www/views.py      |  6 ++++--
 providers/fab/tests/unit/fab/www/test_views.py      | 21 ++++++++++++++++++++-
 2 files changed, 24 insertions(+), 3 deletions(-)

diff --git a/providers/fab/src/airflow/providers/fab/www/views.py 
b/providers/fab/src/airflow/providers/fab/www/views.py
index f89517846ef..a0b0f834d1f 100644
--- a/providers/fab/src/airflow/providers/fab/www/views.py
+++ b/providers/fab/src/airflow/providers/fab/www/views.py
@@ -146,9 +146,11 @@ def redirect(*args, **kwargs):
         # See https://github.com/apache/airflow/pull/55506
         cookie_path = get_cookie_path()
         if AIRFLOW_V_3_1_1_PLUS:
-            response.set_cookie(COOKIE_NAME_JWT_TOKEN, token, 
path=cookie_path, secure=secure, httponly=True)
+            response.set_cookie(
+                COOKIE_NAME_JWT_TOKEN, token, path=cookie_path, secure=secure, 
httponly=True, samesite="Lax"
+            )
         else:
-            response.set_cookie(COOKIE_NAME_JWT_TOKEN, token, 
path=cookie_path, secure=secure)
+            response.set_cookie(COOKIE_NAME_JWT_TOKEN, token, 
path=cookie_path, secure=secure, samesite="Lax")
 
         return response
     return flask_redirect(*args, **kwargs)
diff --git a/providers/fab/tests/unit/fab/www/test_views.py 
b/providers/fab/tests/unit/fab/www/test_views.py
index e859121203a..d9bc7dce22c 100644
--- a/providers/fab/tests/unit/fab/www/test_views.py
+++ b/providers/fab/tests/unit/fab/www/test_views.py
@@ -18,10 +18,12 @@
 from __future__ import annotations
 
 import time
+from unittest import mock
 
 import pytest
-from flask import Flask, session as builtin_flask_session
+from flask import Flask, g, session as builtin_flask_session
 
+from airflow.providers.fab.www import views
 from airflow.providers.fab.www.extensions.init_session import 
SESSION_LOGIN_TIME_KEY
 from airflow.providers.fab.www.views import get_token_expiration_seconds
 
@@ -65,3 +67,20 @@ def 
test_token_expiration_is_uncapped_for_a_session_without_a_login_stamp(app):
     }
     with app.test_request_context(), conf_vars(overrides):
         assert get_token_expiration_seconds() == JWT_EXPIRATION_TIME
+
+
+def test_redirect_sets_samesite_on_token_cookie(app):
+    with app.test_request_context():
+        user = mock.Mock()
+        user.is_authenticated = True
+        g.user = user
+        with (
+            mock.patch("airflow.providers.fab.www.views.get_auth_manager") as 
mock_get_auth_manager,
+            
mock.patch("airflow.providers.fab.www.views.get_token_expiration_seconds", 
return_value=3600),
+            mock.patch("airflow.providers.fab.www.views.get_cookie_path", 
return_value="/"),
+        ):
+            mock_get_auth_manager.return_value.generate_jwt.return_value = 
"token"
+            response = views.redirect("/home")
+    set_cookie = response.headers.get("Set-Cookie")
+    assert set_cookie is not None
+    assert "samesite=lax" in set_cookie.lower()

Reply via email to