Repository navigation
Scope UI next_run_assets endpoint to assets the caller may read - #72862
Merged
Merged
Conversation
henry3260
requested review from
bugraoz93,
choo121600,
ephraimbuddy,
jason810496,
pierrejeambrun,
rawwar and
shubhamraj-git
as code owners
September 10, 2026 05:10
Contributor
Author
|
Note: the |
1 task done
rjgoyln
reviewed
Sep 27, 2026
rjgoyln
left a comment
Contributor
There was a problem hiding this comment.
Looks good to me!
Two notes below: one on the shape this gives the events list, and one on the new test's mock assertion.
Just my thoughts, feel free to resolve them.
Drafted-by: Claude Code (Opus 5); reviewed by @rjgoyln before posting
henry3260
force-pushed
the
fix-next-run-assets-filter
branch
from
September 27, 2026 14:51
183e9bd to
c6e82c1
Compare
This was referenced Sep 27, 2026
pierrejeambrun
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
GET /ui/next_run_assets/{dag_id}now redactsasset_expressionthroughReadableAssetsFilterDep(#72864), but the query behind theeventslist is still filtered bydag_idalone. The class-levelrequires_access_asset("GET")check passesAssetDetails(id=None)to the auth manager, because the route has noasset_idpath parameter, so it only confirms the caller may read assets in general.A caller with read access to a Dag and generic asset read permission therefore still receives the
id,name,uri,asset_inactiveflag and, for partitioned Dags, thereceived_keys/required_keysof upstream assets that a fine-grained auth manager hides from them — the names the expression just redacted come straight back inevents. The siblingGET /ui/assetslist endpoint already scopes its results throughReadableAssetsFilterDep; this endpoint never wired it into the query.What
airflow-core/src/airflow/api_fastapi/core_api/routes/ui/assets.py: apply the already-injectedReadableAssetsFilterDepto the asset query before execution, so theeventslist and the partitioned enrichment only cover assets the caller may read.Note on caller-scoped counts
Unlike the
asset_expressionredaction in #72864, which keeps a hidden slot per unreadable asset to preserve the schedule shape, this drops unreadable rows fromeventsentirely — a hidden asset'sid/name/uriare required fields onNextRunAssetEventResponseand cannot be returned at all without reintroducing the leak.Was generative AI tooling used to co-author this PR?