Apply per-DAG audit log permission to event log detail endpoint#67112
Merged
pierrejeambrun merged 1 commit intoMay 19, 2026
Conversation
Align GET /eventLogs/{event_log_id} with the collection endpoint
GET /eventLogs, which already scopes results to the user's permitted
Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced
the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with
no dag_id.
Introduce requires_access_event_log, mirroring requires_access_backfill:
resolve the dag_id from the event log row, then delegate to
requires_access_dag scoped to that dag_id.
Contributor
Backport successfully created: v3-2-testNote: As of Merging PRs targeted for Airflow 3.X In matter of doubt please ask in #release-management Slack channel.
|
github-actions Bot
pushed a commit
to aws-mwaa/upstream-to-airflow
that referenced
this pull request
May 19, 2026
…dpoint (apache#67112) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
aws-airflow-bot
pushed a commit
to aws-mwaa/upstream-to-airflow
that referenced
this pull request
May 19, 2026
…dpoint (apache#67112) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
pierrejeambrun
added a commit
that referenced
this pull request
May 19, 2026
…dpoint (#67112) (#67159) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
1 task
1 task
vatsrahul1001
pushed a commit
that referenced
this pull request
May 20, 2026
…dpoint (#67112) (#67159) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
vatsrahul1001
pushed a commit
that referenced
this pull request
May 20, 2026
…dpoint (#67112) (#67159) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
vatsrahul1001
pushed a commit
that referenced
this pull request
May 21, 2026
…dpoint (#67112) (#67159) Align GET /eventLogs/{event_log_id} with the collection endpoint GET /eventLogs, which already scopes results to the user's permitted Dags via ReadableEventLogsFilterDep. The detail endpoint only enforced the generic DagAccessEntity.AUDIT_LOG check via requires_access_dag with no dag_id. Introduce requires_access_event_log, mirroring requires_access_backfill: resolve the dag_id from the event log row, then delegate to requires_access_dag scoped to that dag_id. (cherry picked from commit 4498582) Co-authored-by: Pierre Jeambrun <pierrejbrun@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Align
GET /eventLogs/{event_log_id}with the collection endpointGET /eventLogs, which already scopes results to the user's permitted Dags viaReadableEventLogsFilterDep. The detail endpoint only enforced the genericDagAccessEntity.AUDIT_LOGcheck viarequires_access_dagwith nodag_id.Introduce
requires_access_event_log, mirroringrequires_access_backfill: resolve thedag_idfrom the event log row, then delegate torequires_access_dagscoped to thatdag_id.Was generative AI tooling used to co-author this PR?
Generated-by: Claude Code (Opus 4.7) following the guidelines