potiuk opened a new pull request, #72627: URL: https://github.com/apache/airflow/pull/72627
The Edge UI plugin docs say that "can read on Plugins" and "can read on Jobs" let you view the UI and manage the workers, but they don't say how the two permissions differ, or what the default `Viewer` role already holds. Both gaps matter, because the endpoints and the navigation are gated differently: - The worker management endpoints under `/edge_worker/ui/` check **only** `AccessView.JOBS`, and the check is not method-aware — the same dependency guards the GET reads and the POST/PATCH/DELETE mutations. - "can read on Plugins" only controls whether the plugin appears in the UI navigation. It is **not** required in order to call the endpoints. So "can read on Jobs" alone is enough to shut down, delete, re-queue and retune Edge workers, whether or not the plugin is visible to that user. That is intentional — `AccessView.JOBS` is the management permission for the plugin rather than a read-only grant, as #67379 already documents. What is missing is *why* it reads as surprising: from the code alone, a permission named "can read" guards mutating routes. It's more surprising in a default Flask AppBuilder setup, where `VIEWER_PERMISSIONS` includes `(ACTION_CAN_READ, RESOURCE_JOB)` but not the Plugins read — so a Viewer cannot see the Edge plugin and can still reach its management endpoints. This adds a warning to the UI plugin docs stating the intent, the split between the two permissions, the consequence for the default Viewer role, and the concrete action for deployments where Viewers must not manage workers. It points at the existing "fine granular access control" entry in `architecture.rst` rather than restating it. Documentation only; no behaviour change. --- **Gen-AI disclosure:** this PR was prepared with the assistance of Claude Code. The permission facts were verified against `main` before writing: `VIEWER_PERMISSIONS` in the FAB security-manager override, and the `requires_access_view(access_view=AccessView.JOBS)` dependency on each route in `providers/edge3/.../worker_api/routes/ui.py`. I have reviewed the wording and stand behind it. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
