Under which category would you file this issue?
Providers
Apache Airflow version
3.2.2
What happened and how to reproduce it?
LDAP Authentication fails with a referer host mismatch when Airflow 3 is exposed via HTTPRoute and the gateway listener port is different from original port used to access Airflow.
- Deploy Airflow 3 using main helm chart.
- Configure LDAP Authentication for Airflow 3 using apiServerConfig.
- Expose Airflow via HTTPRoute, and gateway listener port is different from the port we reach Airflow.
- Attempt to login, the login will fail.
What you think should happen instead?
The error returned is 'The referrer does not match the host' (HTTP code 400). It is possible due to port mismatch between gateway and referer URL. Disabling XSRF on Flask level works, but it should be avoided, there is a workaround for the issue is to add a filter to the HTTPRoute and delete the X-Forwarded-Port header, however there could be a better approach, I might be missing something.
Operating System
Debian
Deployment
Official Apache Airflow Helm Chart
Apache Airflow Provider(s)
No response
Versions of Apache Airflow Providers
No response
Official Helm Chart version
main (development)
Kubernetes Version
1.35
Helm Chart configuration
Enable httproute with specifying gateway and hostnames
Docker Image customizations
No response
Anything else?
I am willing to submit a PR, if the change is helm based.
Are you willing to submit PR?
Code of Conduct
Under which category would you file this issue?
Providers
Apache Airflow version
3.2.2
What happened and how to reproduce it?
LDAP Authentication fails with a referer host mismatch when Airflow 3 is exposed via HTTPRoute and the gateway listener port is different from original port used to access Airflow.
What you think should happen instead?
The error returned is 'The referrer does not match the host' (HTTP code 400). It is possible due to port mismatch between gateway and referer URL. Disabling XSRF on Flask level works, but it should be avoided, there is a workaround for the issue is to add a filter to the HTTPRoute and delete the X-Forwarded-Port header, however there could be a better approach, I might be missing something.
Operating System
Debian
Deployment
Official Apache Airflow Helm Chart
Apache Airflow Provider(s)
No response
Versions of Apache Airflow Providers
No response
Official Helm Chart version
main (development)
Kubernetes Version
1.35
Helm Chart configuration
Enable httproute with specifying gateway and hostnames
Docker Image customizations
No response
Anything else?
I am willing to submit a PR, if the change is helm based.
Are you willing to submit PR?
Code of Conduct