Skip to content

Hide unreadable assets in the asset expression served by next_run_assets - #72864

Merged
bbovenzi merged 1 commit into
apache:mainfrom
henry3260:fix-asset-expression-redaction
Sep 18, 2026
Merged

bbovenzi merged 1 commit into
apache:mainfrom
henry3260:fix-asset-expression-redaction

Conversation

@henry3260

@henry3260 henry3260 commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Why

DagModel.asset_expression names every upstream asset of a Dag, including their ids, names and uris. GET /ui/next_run_assets/{dag_id} returns it verbatim, so a caller with read access to a Dag can learn the identity of assets a fine-grained auth manager hides from them, even after the events list itself is scoped (#72862).

The expression is written by the Dag processor with no notion of a caller, and the scheduler needs it complete, so it cannot be filtered at write time. It has to be scoped per request, at the API layer, like the asset list endpoints already are.

This is the first of a small series: it introduces the shared redaction helper and the response-shape change, and wires the first endpoint. Follow-ups will wire the public GET /dags/{dag_id}/details, the UI GET /ui/dags list, and the UI rendering of a hidden leaf.

What

  • airflow-core/src/airflow/api_fastapi/common/asset_expression.py: new redact_asset_expression helper. It walks the all / any tree and replaces every asset leaf whose id the caller may not read with {"uri": null, "name": null, "id": null, "group": ..., "hidden": true}. The slot is kept so the shape of the schedule stays honest instead of silently dropping a condition. A leaf without an id fails closed. alias and asset_ref leaves are left as-is (no batch authorization exists for aliases; refs are unresolved names by design). The input is never mutated, since it lives on an ORM row whose session commits on exit.
  • airflow-core/src/airflow/api_fastapi/core_api/datamodels/common.py: AssetExpressionAssetInfo gains hidden: bool = False, and uri / name become nullable to carry a redacted leaf.
  • airflow-core/src/airflow/api_fastapi/core_api/routes/ui/assets.py: next_run_assets injects ReadableAssetsFilterDep and serves the redacted expression on all three return paths.

Was generative AI tooling used to co-author this PR?
  • Yes — Claude Code (Claude Fable 5.1)

@bbovenzi
bbovenzi merged commit 9dcd6a0 into apache:main Sep 18, 2026
305 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API area:UI Related to UI/UX. For Frontend Developers.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants