Skip to content

Require edit rights for async connection test updates#68127

Open
gopidesupavan wants to merge 1 commit into
apache:mainfrom
gopidesupavan:fix-async-connection-test-authorization-issue
Open

Require edit rights for async connection test updates#68127
gopidesupavan wants to merge 1 commit into
apache:mainfrom
gopidesupavan:fix-async-connection-test-authorization-issue

Conversation

@gopidesupavan
Copy link
Copy Markdown
Member

Fixes an authorization bypass where async connection tests with commit_on_success=true could overwrite existing connections using only create permission instead of requiring edit permission.


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

@gopidesupavan
Copy link
Copy Markdown
Member Author

cc: @anishgirianish

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant