apache/airflow

Never expose sensitive config values in UI

Geschlossen

#59.860 geöffnet am 27.12.2025

 (5 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)Python (16.781 Forks)batch import
area:APIarea:UIgood first issue

Repository-Metriken

Stars
 (44.809 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 7T 18h) (834 gemergte PRs in 30 T)

Beschreibung

Body

Currently the expose config allows deployment manager to expose also sensitive data - when set to True https://airflow.apache.org/docs/apache-airflow/stable/configurations-ref.html#expose-config. The non-sensitive-only value causes sensitive field masking.

With the discussion mentioned in #59838 we agreed that we should never expose sensitive data over any public API where UI user can authenticate (only via task-sdk API where tasks get dedicated JWT token)

This means that:

  • Only True/False should be expected for expose-config and True means that sensitive fields are masked
  • We should add fallback - when "non-sensitive-data" is set for the parameter it should be treated as True and deprecation warning should be raised
  • newsfragment should be added explaining the behaviour change

Committer

  • I acknowledge that I am a maintainer/committer of the Apache Airflow project.

Contributor Guide