Skip to content

Airflow 2.7 Webserver unreacheable with new authentication manager #33586

Description

@cesar-vermeulen

Apache Airflow version

2.7.0

What happened

When connecting to the Airflow UI, we get the following message:

> Python version: 3.11.4
> Airflow version: 2.7.0
> Node: redact
> -------------------------------------------------------------------------------
> Error! Please contact server admin.

If we investigate further and we look at the Kubernetes pod logs, we see that following error message is thrown:

File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/views.py", line 989, in index
return self.render_template(
^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/views.py", line 694, in render_template
return super().render_template(
^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/baseviews.py", line 339, in render_template
return render_template(
^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/flask/templating.py", line 147, in render_template
return _render(app, template, context)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/flask/templating.py", line 130, in _render
rv = template.render(context)
^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/jinja2/environment.py", line 1301, in render
self.environment.handle_exception()
File "/home/airflow/.local/lib/python3.11/site-packages/jinja2/environment.py", line 936, in handle_exception
raise rewrite_traceback_stack(source=source)
File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/templates/airflow/dags.html", line 44, in top-level template code
{% elif curr_ordering_direction == 'asc' and request.args.get('sorting_key') == attribute_name %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/templates/airflow/main.html", line 21, in top-level template code
{% from 'airflow/_messages.html' import show_message %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/templates/appbuilder/baselayout.html", line 2, in top-level template code
{% import 'appbuilder/baselib.html' as baselib %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/templates/appbuilder/init.html", line 42, in top-level template code
{% block body %}
File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/templates/appbuilder/baselayout.html", line 8, in block 'body'
{% block navbar %}
File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/templates/appbuilder/baselayout.html", line 10, in block 'navbar'
{% include 'appbuilder/navbar.html' %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/templates/appbuilder/navbar.html", line 53, in top-level template code
{% include 'appbuilder/navbar_right.html' %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/airflow/www/templates/appbuilder/navbar_right.html", line 71, in top-level template code
{% for name in user_names %}{{ name[0].upper() }}{% endfor %}
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/airflow/.local/lib/python3.11/site-packages/jinja2/environment.py", line 485, in getattr
return getattr(obj, attribute)
^^^^^^^^^^^^^^^^^^^^^^^
jinja2.exceptions.UndefinedError: str object has no element 0

What you think should happen instead

Show the Airflow UI

How to reproduce

The deployment is done using the official Airflow helm chart with Azure AD authentication on the webserver.

As soon as we did the upgrade to Airflow 2.7, the webserver became unreacheable when trying to access it with the error shown above.

Operating System

Debian GNU/Linux 11 (bullseye)

Versions of Apache Airflow Providers

apache-airflow-providers-cncf-kubernetes==7.4.2
apache-airflow-providers-docker==3.6.0
apache-airflow-providers-microsoft-azure==4.3.0

Deployment

Official Apache Airflow Helm Chart

Deployment details

Webserver config:
AUTH_TYPE = AUTH_OAUTH
AUTH_ROLE_ADMIN = 'Admin'
AUTH_USER_REGISTRATION = True
AUTH_USER_REGISTRATION_ROLE = "Admin"

OAUTH_PROVIDERS = [
{
"name": "azure",
"icon": "fa-microsoft",
"token_key": "access_token",
"remote_app": {
"client_id": "${airflow_client_id}",
"client_secret": "${airflow_client_secret}",
"api_base_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2",
"client_kwargs": {
"scope": "User.read name preferred_username email profile",
"resource": "${airflow_client_id}",
},
"request_token_url": None,
"access_token_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2/token",
"authorize_url": "https://login.microsoftonline.com/${airflow_tenant_id}/oauth2/authorize",
},
},
]

Anything else

No response

Are you willing to submit PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Activity

  1. added this to the Airflow 2.7.1 milestone on Aug 21, 2023
  2. vincbeck commented on Aug 21, 2023

    @vincbeck
    Contributor

    Interesting use case. Could you provide what is the first name and last name of the user you are using?

  3. cesar-vermeulen commented on Aug 22, 2023

    @cesar-vermeulen
    Author

    These are not set; this is a screenshot of same user but in different (Airflow 2.6.2) environment:
    image

    I checked our Azure AD and there the first and lastname where not set. I asked our system admins to set these, and retried, but did not work. The screenshot above is also from after these updates.

  4. rjtshrm commented on Aug 22, 2023

    @rjtshrm

    The issue can be resolved it you manually update the first_name and the last_name in the airflow db ab_user. For me it worked. Although it is not a good way, it should be done automatically I guess after the upgrade. Let me know, if it is resolved in automatic way ;)

  5. vincbeck commented on Aug 22, 2023

    @vincbeck
    Contributor

    But this is something we definitely should handle. I'll create a PR to fix it. Thanks for the heads up!

  6. rjtshrm commented on Aug 22, 2023

    @rjtshrm

    But why is it Mandatory in 2.7, earlier version works fine without first and last name

  7. vincbeck commented on Aug 22, 2023

    @vincbeck
    Contributor

    When implementing #32217 which caused the issue, I thought this use case (no first name and no last name) did not exist. I was wrong. #33617 fixes the bug

  8. vincbeck commented on Aug 22, 2023

    @vincbeck
    Contributor

    But why is it Mandatory in 2.7, earlier version works fine without first and last name

    It is still not mandatory, it is a bug

  9. potiuk commented on Aug 22, 2023

    @potiuk
    Member

    Scheduled for 2.7.1.

  10. rjtshrm commented on Aug 23, 2023

    @rjtshrm

    Thanks @vincbeck. There is another issue when using oauth auth, I get error on login but it was working fine on previous version of airflow

    [2023-08-23T11:27:20.737+0000] {manager.py:1129} ERROR - OAUTH userinfo does not have username or email {}
    [2023-08-23T11:27:20.738+0000] {app.py:1744} ERROR - Exception on /oauth-authorized/aws_cognito [GET]
    Traceback (most recent call last):
      File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 2529, in wsgi_app
        response = self.full_dispatch_request()
                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
      File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1825, in full_dispatch_request
        rv = self.handle_user_exception(e)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
      File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1823, in full_dispatch_request
        rv = self.dispatch_request()
             ^^^^^^^^^^^^^^^^^^^^^^^
      File "/home/airflow/.local/lib/python3.11/site-packages/flask/app.py", line 1799, in dispatch_request
        return self.ensure_sync(self.view_functions[rule.endpoint])(**view_args)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
      File "/home/airflow/.local/lib/python3.11/site-packages/flask_appbuilder/security/views.py", line 693, in oauth_authorized
        return redirect(self.appbuilder.get_url_for_login)
                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
    AttributeError: 'AirflowAppBuilder' object has no attribute 'get_url_for_login'
    

    Do you have any idea about this behaviour?

  11. beatstream69 commented on Aug 23, 2023

    @beatstream69

    Same issue as above, reverting to 2.6.3 =(

  12. rjtshrm commented on Aug 23, 2023

    @rjtshrm

    After some debugging found that in earlier version we were using FAB_SECURITY_MANAGER_CLASS to override the custom auth. But here it is expecting it to SECURITY_MANAGER_CLASS.

    security_manager_class = app.config.get("SECURITY_MANAGER_CLASS") or AirflowSecurityManager

    As it can be seen that if SECURITY_MANAGER_CLASS is not set then it uses default AirflowSecurityManager where the custom auth login for aws cognito was missing and hence was getting the error.

    Although in the airflow 2.7.0 docs https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html, FAB_SECURITY_MANAGER_CLASS is mentioned.

    Also, make sure SECURITY_MANAGER_CLASS to class type not a string as in FAB_SECURITY_MANAGER_CLASS.

    @potiuk @vincbeck Can you confirm this behaviour or am i missing something

  13. vincbeck commented on Aug 23, 2023

    @vincbeck
    Contributor

    @rjtshrm. Yep, looks like another issue. I removed get_url_for_login because we no longer use it but I did not know it was used internally by FAB. Definitely some test missing here. I should have tested with oauth. Fix here: #33660

  14. vincbeck commented on Aug 23, 2023

    @vincbeck
    Contributor

    @potiuk @vincbeck Can you confirm this behaviour or am i missing something

    You are correct, thanks for the catch! It is definitely an error in the documentation which I also fixed as part of #33660. But this is a documentation glitch only, in the code it has been SECURITY_MANAGER_CLASS for a while

  15. rjtshrm commented on Aug 23, 2023

    @rjtshrm

    Thanks @vincbeck , so ideally we should use SECURITY_MANAGER_CLASS instead of the FAB one.

  16. vincbeck commented on Aug 23, 2023

    @vincbeck
    Contributor

    Correct. FAB_SECURITY_MANAGER_CLASS does not exist

  17. potiuk commented on Aug 23, 2023

    @potiuk
    Member

    @rjtshrm - just to make it clear for the future. I think you need to test yourself and see what works. Looks like for now that's a solution and @vincbeck corrected it in the docs - if it works for you - that's cool - we are also marking the fix for 2.7.1 and will continue fixing bugs. .

    But just a future note I think after AIP-56 is out (https://cwiki.apache.org/confluence/display/AIRFLOW/AIP-56+Extensible+user+management) we will strongly encourage users to switch to other mechanisms than FAB. We won't be investing almost any effort in FAB, and mostly relying on users helping each other with problems rather than users relying on authoritatve answers from maintainers (and 100% backwards compatiobily) because we collectively have almost no expertise in it and decided to move away from it. That's maybe a brutal, but reality. The errors in our documentation that have been there for quite a while are also a sign that it's not a high priority from us.

    It also might change in the future in subtle ways. It's not a part of our Public Interface https://airflow.apache.org/docs/apache-airflow/stable/public-airflow-interface.html so it might change similarly as at some point in tine FAB_SECURITY_MANAGER_CLASS changed to SECURITY_MANAGER_CLASS. Also FAB on it's own changes it's features and behaviours and we had in the past many backwards-incompatible changes with it - and we had neither way or intention to keep backwards compatible,. This is one reason why it is not part of our public interface (and does not follow our SemVer promises) and why we are moving away from it.

    Only AIP-56 will be the "official API" that will be meant to be tested and "stable" in the future.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:corekind:bugThis is a clearly a bugneeds-triagelabel for new issues that we didn't triage yet

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions