flcrom opened a new pull request, #44605: URL: https://github.com/apache/superset/pull/44605
### SUMMARY Flash messages written by Superset and FAB views were never consumed: no code path called get_flashed_messages(). Messages (including failed-login warnings) accumulated in the signed session cookie on every request, growing it until proxies reject the oversized headers with a 502 (#44541). The login page never displayed them either, working around it with a sessionStorage TODO hack. - Drain the flash queue in the login view and pass the messages to the SPA as per-request bootstrap data (auth_messages), never via the memoized common bootstrap payload. - The Login page renders them as toasts (danger, warning, info, success by category) and clears the password field on errors; the sessionStorage workaround is removed. ### TESTING INSTRUCTIONS 1. Log out, submit a wrong password repeatedly: before, flash entries accumulate in the session cookie (decode it to see them) and it grows every request; after, each message renders as a toast exactly once and the session stays empty. 2. pytest tests/unit_tests/views/test_auth_login.py 3. cd superset-frontend && npx jest src/pages/Login ### ADDITIONAL INFORMATION - [x] Has associated issue: Fixes #44541 - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
