Angaben zum Datum
Datum aus der Quelle.
Aufgenommen am .
Apache Airflow 3.3.2: Backfill-Endpunkte geben keine IDs mehr preis
In Apache Airflow 3.3.2 geben die Backfill-Endpunkte nicht mehr preis, welche Backfill-IDs über Dags hinweg existieren: Der Zugriff wird nur noch anhand des im Pfad genannten Backfills autorisiert, und ein Backfill auf einem nicht lesbaren Dag liefert nun "404" (Backfill not found) statt "403".
📦 PyPI: https://pypi.org/project/apache-airflow/3.3.2/ 📚 Docs: https://airflow.apache.org/docs/apache-airflow/3.3.2/ 🛠 Release Notes: https://airflow.apache.org/docs/apache-airflow/3.3.2/release_notes.html 🐳 Docker Image: "docker pull apache/airflow:3.3.2" 🚏 Constraints: https://github.com/apache/airflow/tree/constraints-3.3.2
Significant Changes
Backfill endpoints no longer disclose which backfill ids exist across Dags
The four routes that name a backfill in their path -- GET /backfills/{backfill_id}
and the pause, unpause and cancel routes -- resolved the Dag they authorize
against from the dag_id supplied on the request whenever the path's id matched no row.
An unknown id and a backfill on a Dag the caller cannot see therefore answered differently,
which enumerates backfill ids across Dags.
The backfill named in the path is now the only thing those routes authorize against.
Behaviour changes:
- Requesting a backfill on a Dag the caller cannot read now returns
404(Backfill not found) -- the same response an unknown id gets -- instead of the403returned before. A caller who can read the Dag still gets403for a write they are not allowed to make. - A
backfill_idin the path is never authorized against adag_idin the request body or query string.GET /backfills,POST /backfillsandPOST /backfills/dry_run…