Generate fab permission table - #72230
Merged
Merged
Conversation
baha-bouali
requested review from
amoghrajesh,
ashb,
bugraoz93,
gopidesupavan,
jason810496,
jscheffl,
potiuk and
vincbeck
as code owners
August 28, 2026 18:47
vincbeck
approved these changes
Sep 2, 2026
Contributor
Backport failed to create: v3-3-test. View the failure log Run detailsNote: As of Merging PRs targeted for Airflow 3.X In matter of doubt please ask in #release-management Slack channel.
You can attempt to backport this manually by running: cherry_picker 3e93c77 v3-3-testThis should apply the commit to the v3-3-test branch and leave the commit in conflict state marking After you have resolved the conflicts, you can continue the backport process by running: cherry_picker --continueIf you don't have cherry-picker installed, see the installation guide. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The FAB permission table in
providers/fab/docs/auth-manager/access-control.rstismaintained by hand and has drifted. This generates it from the route definitions instead,
and adds a prek hook so it stays in sync.
#67606 already did this for the core table. This does the same for FAB's, which needs
FAB-specific permission names and the minimum-role column.
The drift
The hand-written table has 57 rows; the API exposes 143.
/poolsGET saysOp, butVIEWER_PERMISSIONSgrants it toViewer./eventLogsGET omits the baseDAGs.can_readrequirement that is actually enforced.clearTaskInstanceslisted asPUTwhen the route isPOST.How
scripts/ci/prek/fab_permissions_doc.pyreusesextract_permissions.py's parser andrenders the FAB view from the same entries. It reads FAB's own resource maps and role
definitions rather than restating them, and runs statically via
ast— no Airflow importneeded.
The table is written in place between markers, following
check_integrations_list.py.Verification
Regenerate with
prek run generate-fab-permissions-doc --all-files.Closes #43430