Repository navigation
Airflow 2.7 Webserver unreacheable with new authentication manager #33586
Description
Activity
- addedkind:bugThis is a clearly a bugThis is a clearly a bugneeds-triagelabel for new issues that we didn't triage yetlabel for new issues that we didn't triage yet
on Aug 21, 2023 Interesting use case. Could you provide what is the first name and last name of the user you are using?
The issue can be resolved it you manually update the first_name and the last_name in the airflow db ab_user. For me it worked. Although it is not a good way, it should be done automatically I guess after the upgrade. Let me know, if it is resolved in automatic way ;)
But this is something we definitely should handle. I'll create a PR to fix it. Thanks for the heads up!
But why is it Mandatory in 2.7, earlier version works fine without first and last name
But why is it Mandatory in 2.7, earlier version works fine without first and last name
It is still not mandatory, it is a bug
Scheduled for 2.7.1.
Thanks @vincbeck. There is another issue when using oauth auth, I get error on login but it was working fine on previous version of airflow
[2023-08-23T11:27:20.737+0000] {manager.py:1129} ERROR - OAUTH userinfo does not have username or email {} [2023-08-23T11:27:20.738+0000] {app.py:1744} ERROR - Exception on /oauth-authorized/aws_cognito [GET] Traceback (most recent call last): File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 2529, in wsgi_app response = self.full_dispatch_request() ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1825, in full_dispatch_request rv = self.handle_user_exception(e) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1823, in full_dispatch_request rv = self.dispatch_request() ^^^^^^^^^^^^^^^^^^^^^^^ File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1799, in dispatch_request return self.ensure_sync(self.view_functions[rule.endpoint])(**view_args) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/security/views.py", line 693, in oauth_authorized return redirect(self.appbuilder.get_url_for_login) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ AttributeError: 'AirflowAppBuilder' object has no attribute 'get_url_for_login'Do you have any idea about this behaviour?
Reacted by David KalamaridesSame issue as above, reverting to 2.6.3 =(
After some debugging found that in earlier version we were using FAB_SECURITY_MANAGER_CLASS to override the custom auth. But here it is expecting it to SECURITY_MANAGER_CLASS.
security_manager_class = app.config.get("SECURITY_MANAGER_CLASS") or AirflowSecurityManager As it can be seen that if SECURITY_MANAGER_CLASS is not set then it uses default AirflowSecurityManager where the custom auth login for aws cognito was missing and hence was getting the error.
Although in the airflow 2.7.0 docs https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html, FAB_SECURITY_MANAGER_CLASS is mentioned.
Also, make sure SECURITY_MANAGER_CLASS to class type not a string as in FAB_SECURITY_MANAGER_CLASS.
@potiuk @vincbeck Can you confirm this behaviour or am i missing something
Thanks @vincbeck , so ideally we should use SECURITY_MANAGER_CLASS instead of the FAB one.
Correct.
FAB_SECURITY_MANAGER_CLASSdoes not exist@rjtshrm - just to make it clear for the future. I think you need to test yourself and see what works. Looks like for now that's a solution and @vincbeck corrected it in the docs - if it works for you - that's cool - we are also marking the fix for 2.7.1 and will continue fixing bugs. .
But just a future note I think after AIP-56 is out (https://cwiki.apache.org/confluence/display/AIRFLOW/AIP-56+Extensible+user+management) we will strongly encourage users to switch to other mechanisms than FAB. We won't be investing almost any effort in FAB, and mostly relying on users helping each other with problems rather than users relying on authoritatve answers from maintainers (and 100% backwards compatiobily) because we collectively have almost no expertise in it and decided to move away from it. That's maybe a brutal, but reality. The errors in our documentation that have been there for quite a while are also a sign that it's not a high priority from us.
It also might change in the future in subtle ways. It's not a part of our Public Interface https://airflow.apache.org/docs/apache-airflow/stable/public-airflow-interface.html so it might change similarly as at some point in tine FAB_SECURITY_MANAGER_CLASS changed to SECURITY_MANAGER_CLASS. Also FAB on it's own changes it's features and behaviours and we had in the past many backwards-incompatible changes with it - and we had neither way or intention to keep backwards compatible,. This is one reason why it is not part of our public interface (and does not follow our SemVer promises) and why we are moving away from it.
Only AIP-56 will be the "official API" that will be meant to be tested and "stable" in the future.

Apache Airflow version
2.7.0
What happened
When connecting to the Airflow UI, we get the following message:
If we investigate further and we look at the Kubernetes pod logs, we see that following error message is thrown:
What you think should happen instead
Show the Airflow UI
How to reproduce
The deployment is done using the official Airflow helm chart with Azure AD authentication on the webserver.
As soon as we did the upgrade to Airflow 2.7, the webserver became unreacheable when trying to access it with the error shown above.
Operating System
Debian GNU/Linux 11 (bullseye)
Versions of Apache Airflow Providers
apache-airflow-providers-cncf-kubernetes==7.4.2
apache-airflow-providers-docker==3.6.0
apache-airflow-providers-microsoft-azure==4.3.0
Deployment
Official Apache Airflow Helm Chart
Deployment details
Webserver config:
AUTH_TYPE = AUTH_OAUTH
AUTH_ROLE_ADMIN = 'Admin'
AUTH_USER_REGISTRATION = True
AUTH_USER_REGISTRATION_ROLE = "Admin"
OAUTH_PROVIDERS = [
{
"name": "azure",
"icon": "fa-microsoft",
"token_key": "access_token",
"remote_app": {
"client_id": "${airflow_client_id}",
"client_secret": "${airflow_client_secret}",
"api_base_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2",
"client_kwargs": {
"scope": "User.read name preferred_username email profile",
"resource": "${airflow_client_id}",
},
"request_token_url": None,
"access_token_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2/token",
"authorize_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2/authorize",
},
},
]
Anything else
No response
Are you willing to submit PR?
Code of Conduct