potiuk opened a new pull request, #72627:
URL: https://github.com/apache/airflow/pull/72627

   The Edge UI plugin docs say that "can read on Plugins" and "can read on 
Jobs" let you view the UI and manage the workers, but they don't say how the 
two permissions differ, or what the default `Viewer` role already holds.
   
   Both gaps matter, because the endpoints and the navigation are gated 
differently:
   
   - The worker management endpoints under `/edge_worker/ui/` check **only** 
`AccessView.JOBS`, and the check is not method-aware — the same dependency 
guards the GET reads and the POST/PATCH/DELETE mutations.
   - "can read on Plugins" only controls whether the plugin appears in the UI 
navigation. It is **not** required in order to call the endpoints.
   
   So "can read on Jobs" alone is enough to shut down, delete, re-queue and 
retune Edge workers, whether or not the plugin is visible to that user.
   
   That is intentional — `AccessView.JOBS` is the management permission for the 
plugin rather than a read-only grant, as #67379 already documents. What is 
missing is *why* it reads as surprising: from the code alone, a permission 
named "can read" guards mutating routes. It's more surprising in a default 
Flask AppBuilder setup, where `VIEWER_PERMISSIONS` includes `(ACTION_CAN_READ, 
RESOURCE_JOB)` but not the Plugins read — so a Viewer cannot see the Edge 
plugin and can still reach its management endpoints.
   
   This adds a warning to the UI plugin docs stating the intent, the split 
between the two permissions, the consequence for the default Viewer role, and 
the concrete action for deployments where Viewers must not manage workers. It 
points at the existing "fine granular access control" entry in 
`architecture.rst` rather than restating it.
   
   Documentation only; no behaviour change.
   
   ---
   
   **Gen-AI disclosure:** this PR was prepared with the assistance of Claude 
Code. The permission facts were verified against `main` before writing: 
`VIEWER_PERMISSIONS` in the FAB security-manager override, and the 
`requires_access_view(access_view=AccessView.JOBS)` dependency on each route in 
`providers/edge3/.../worker_api/routes/ui.py`. I have reviewed the wording and 
stand behind it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to