Skip to content

Conversation

@suhail-zemoso
Copy link
Contributor

✅ Fix: Apply DAG permission filter to /dag_stats and /historical_metrics_data endpoint

📌 Closes: #53938

🔍 Summary
This PR addresses a security/visibility issue where the /dag_stats and /historical_metrics_data endpoints returned data for all DAGs, even if the requesting user lacked the necessary permissions.

To resolve this, DAG-level permission checks are now enforced using ReadableDagsFilterDep.

🛠️ What was changed
✅ Added readable_dags_filter: ReadableDagsFilterDep as a dependency to:

  1. /dag_stats (returns count of DAGs in various states)
  2. /historical_metrics_data (returns historical task run data)

✅ Ensured that only data from DAGs the current user has access to is included in the response


^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@boring-cyborg
Copy link

boring-cyborg bot commented Aug 5, 2025

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide (https://github.com/apache/airflow/blob/main/contributing-docs/README.rst)
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our pre-commits will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@boring-cyborg boring-cyborg bot added the area:API Airflow's REST/HTTP API label Aug 5, 2025
@pierrejeambrun pierrejeambrun added this to the Airflow 3.0.5 milestone Aug 6, 2025
@pierrejeambrun pierrejeambrun added the backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch label Aug 6, 2025
@pierrejeambrun pierrejeambrun merged commit 5964ab5 into apache:main Aug 7, 2025
197 of 198 checks passed
@boring-cyborg
Copy link

boring-cyborg bot commented Aug 7, 2025

Awesome work, congrats on your first merged pull request! You are invited to check our Issue Tracker for additional contributions.

github-actions bot pushed a commit that referenced this pull request Aug 7, 2025
) (#54126)

(cherry picked from commit 5964ab5)

Co-authored-by: suhail-zemoso <suhail.gour@zemosolabs.com>
@github-actions
Copy link

github-actions bot commented Aug 7, 2025

Backport successfully created: v3-0-test

Status Branch Result
v3-0-test PR Link

github-actions bot pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
…che#53938) (apache#54126)

(cherry picked from commit 5964ab5)

Co-authored-by: suhail-zemoso <suhail.gour@zemosolabs.com>
pierrejeambrun pushed a commit that referenced this pull request Aug 7, 2025
) (#54126) (#54215)

(cherry picked from commit 5964ab5)

Co-authored-by: suhail-zemoso <suhail.gour@zemosolabs.com>
github-actions bot pushed a commit to astronomer/airflow that referenced this pull request Aug 7, 2025
…che#53938) (apache#54126)

(cherry picked from commit 5964ab5)

Co-authored-by: suhail-zemoso <suhail.gour@zemosolabs.com>
ferruzzi pushed a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Aug 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UI - Home screen does not filter based on logged in user's role's access to dags

2 participants