flcrom opened a new pull request, #44605:
URL: https://github.com/apache/superset/pull/44605

   ### SUMMARY
   Flash messages written by Superset and FAB views were never consumed: no 
code path called get_flashed_messages(). Messages (including failed-login 
warnings) accumulated in the signed session cookie on every request, growing it 
until proxies reject the oversized headers with a 502 (#44541). The login page 
never displayed them either, working around it with a sessionStorage TODO hack.
   
   - Drain the flash queue in the login view and pass the messages to the SPA 
as per-request bootstrap data (auth_messages), never via the memoized common 
bootstrap payload.
   - The Login page renders them as toasts (danger, warning, info, success by 
category) and clears the password field on errors; the sessionStorage 
workaround is removed.
   
   ### TESTING INSTRUCTIONS
   1. Log out, submit a wrong password repeatedly: before, flash entries 
accumulate in the session cookie (decode it to see them) and it grows every 
request; after, each message renders as a toast exactly once and the session 
stays empty.
   2. pytest tests/unit_tests/views/test_auth_login.py
   3. cd superset-frontend && npx jest src/pages/Login
   
   ### ADDITIONAL INFORMATION
   - [x] Has associated issue: Fixes #44541
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to