Repository navigation
Conversation
Lee-W
force-pushed
the
asset-auth-filter-perf
branch
from
October 5, 2026 12:00
0fc3dce to
4fa1cf2
Compare
Scoping asset API responses to what a user may read (apache#72682) gave BaseAuthManager a default that loads the id, name and uri of every asset and then asks is_authorized_asset about each row. Simple auth manager grants asset access by role alone and never inspects the asset it is asked about, so that loop re-derives a single constant answer once per row, along with the name and uri it only loads to build the details it then ignores. The auth managers whose is_authorized_asset makes a remote call were given batched overrides at the time; simple auth manager, which is the default, was left on the generic path.
Simple auth manager now overrides get_authorized_assets, and it is the auth manager the API tests run against. The asset route tests that scope responses to readable assets patched the method on BaseAuthManager, so the override bypassed the patch and the tests stopped exercising the filtering they assert on.
Lee-W
force-pushed
the
asset-auth-filter-perf
branch
from
October 6, 2026 16:13
4fa1cf2 to
7b1a2c2
Compare
Lee-W
marked this pull request as ready for review
October 6, 2026 20:59
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scoping asset API responses to what a user may read (#72682) gave BaseAuthManager a default that loads the id, name and uri of every asset and then asks is_authorized_asset about each row. Simple auth manager grants asset access by role alone and never inspects the asset it is asked about, so that loop re-derives a single constant answer once per row, and listing one page of assets costs time proportional to the size of the asset table rather than to the page.
The auth managers whose is_authorized_asset makes a remote call were given batched overrides at the time; simple auth manager, which is the default, was left on the generic path.
Was generative AI tooling used to co-author this PR?
Generated-by: [Claude] following the guidelines
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.