Skip to content

FAB: fix 403 from roles endpoint despite admin rights - #64097

Merged
vincbeck merged 2 commits into
apache:mainfrom
Dev-iL:2603/fab_patch
Mar 23, 2026
Merged

FAB: fix 403 from roles endpoint despite admin rights#64097
vincbeck merged 2 commits into
apache:mainfrom
Dev-iL:2603/fab_patch

Conversation

@Dev-iL

@Dev-iL Dev-iL commented Mar 23, 2026

Copy link
Copy Markdown
Collaborator

This PR addresses the CI failures in the approved version of #63359.

related: #63359
closes: #59510


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

Generated-by: Claude Opus 4.6 following the guidelines


  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

YoannAbriel and others added 2 commits March 23, 2026 11:27
Widen `_MAP_METHOD_NAME_TO_FAB_ACTION_NAME` from `dict[ExtendedResourceMethod, str]`
to `dict[str, str]` and add a `"PATCH" -> ACTION_CAN_EDIT` entry so that
PATCH endpoints resolve to the correct FAB permission without extending
the auth-model enums.

Closes: apache#59510
…ag_ids

The PATCH→can_edit entry added in 839e2e9 broke get_authorized_dag_ids
for PUT requests. The method used the *reverse* map (action→method) to
match permissions, but reversing a many-to-one map (PUT and PATCH both
map to can_edit) silently dropped PUT in favour of PATCH.

Switch to the forward map instead: look up the FAB action for the
incoming HTTP method once, then compare directly against each
permission's action name. This is both correct for aliased methods and
simpler.
@Dev-iL
Dev-iL requested a review from vincbeck as a code owner March 23, 2026 09:30
@eladkal eladkal changed the title 2603/fab patch fix FAB roles endpoint returns 403 with admin rights Mar 23, 2026
@Dev-iL Dev-iL changed the title fix FAB roles endpoint returns 403 with admin rights FAB: fix 403 from roles endpoint despite admin rights Mar 23, 2026
@vincbeck
vincbeck merged commit 0f68191 into apache:main Mar 23, 2026
93 of 94 checks passed
@Dev-iL
Dev-iL deleted the 2603/fab_patch branch March 24, 2026 11:57
aaron-y-chen pushed a commit to aaron-y-chen/airflow that referenced this pull request Mar 30, 2026
* fix(providers/fab): map PATCH to can_edit in FAB action map

Widen `_MAP_METHOD_NAME_TO_FAB_ACTION_NAME` from `dict[ExtendedResourceMethod, str]`
to `dict[str, str]` and add a `"PATCH" -> ACTION_CAN_EDIT` entry so that
PATCH endpoints resolve to the correct FAB permission without extending
the auth-model enums.

Closes: apache#59510

* fix(providers/fab): use forward method→action map in get_authorized_dag_ids

The PATCH→can_edit entry added in 839e2e9 broke get_authorized_dag_ids
for PUT requests. The method used the *reverse* map (action→method) to
match permissions, but reversing a many-to-one map (PUT and PATCH both
map to can_edit) silently dropped PUT in favour of PATCH.

Switch to the forward map instead: look up the FAB action for the
incoming HTTP method once, then compare directly against each
permission's action name. This is both correct for aliased methods and
simpler.

---------

Co-authored-by: Yoann Abriel <yoann.abriel@gmail.com>
Suraj-kumar00 pushed a commit to Suraj-kumar00/airflow that referenced this pull request Apr 7, 2026
* fix(providers/fab): map PATCH to can_edit in FAB action map

Widen `_MAP_METHOD_NAME_TO_FAB_ACTION_NAME` from `dict[ExtendedResourceMethod, str]`
to `dict[str, str]` and add a `"PATCH" -> ACTION_CAN_EDIT` entry so that
PATCH endpoints resolve to the correct FAB permission without extending
the auth-model enums.

Closes: apache#59510

* fix(providers/fab): use forward method→action map in get_authorized_dag_ids

The PATCH→can_edit entry added in 839e2e9 broke get_authorized_dag_ids
for PUT requests. The method used the *reverse* map (action→method) to
match permissions, but reversing a many-to-one map (PUT and PATCH both
map to can_edit) silently dropped PUT in favour of PATCH.

Switch to the forward map instead: look up the FAB action for the
incoming HTTP method once, then compare directly against each
permission's action name. This is both correct for aliased methods and
simpler.

---------

Co-authored-by: Yoann Abriel <yoann.abriel@gmail.com>
abhijeets25012-tech pushed a commit to abhijeets25012-tech/airflow that referenced this pull request Apr 9, 2026
* fix(providers/fab): map PATCH to can_edit in FAB action map

Widen `_MAP_METHOD_NAME_TO_FAB_ACTION_NAME` from `dict[ExtendedResourceMethod, str]`
to `dict[str, str]` and add a `"PATCH" -> ACTION_CAN_EDIT` entry so that
PATCH endpoints resolve to the correct FAB permission without extending
the auth-model enums.

Closes: apache#59510

* fix(providers/fab): use forward method→action map in get_authorized_dag_ids

The PATCH→can_edit entry added in 839e2e9 broke get_authorized_dag_ids
for PUT requests. The method used the *reverse* map (action→method) to
match permissions, but reversing a many-to-one map (PUT and PATCH both
map to can_edit) silently dropped PUT in favour of PATCH.

Switch to the forward map instead: look up the FAB action for the
incoming HTTP method once, then compare directly against each
permission's action name. This is both correct for aliased methods and
simpler.

---------

Co-authored-by: Yoann Abriel <yoann.abriel@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FAB roles endpoint returns 403 with admin rights

4 participants