Add an env var for controlling whether to enable GraphQL routes authorization#19504
Merged
WeichenXu123 merged 3 commits intomlflow:masterfrom Dec 19, 2025
Merged
Add an env var for controlling whether to enable GraphQL routes authorization#19504WeichenXu123 merged 3 commits intomlflow:masterfrom
WeichenXu123 merged 3 commits intomlflow:masterfrom
Conversation
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Contributor
There was a problem hiding this comment.
Pull request overview
This PR adds an environment variable to control whether GraphQL routes authorization is enabled in the MLflow server, as a follow-up to PR #19278. The default value is True, maintaining existing behavior while allowing users to opt-out if needed.
- Added
MLFLOW_SERVER_ENABLE_GRAPHQL_AUTHenvironment variable with a default value ofTrue - Modified
get_graphql_authorization_middleware()to check this environment variable before checking if auth is enabled
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
mlflow/environment_variables.py |
Defines the new MLFLOW_SERVER_ENABLE_GRAPHQL_AUTH boolean environment variable with default value True |
mlflow/server/auth/__init__.py |
Imports and uses the new environment variable in get_graphql_authorization_middleware() to allow disabling GraphQL authorization |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
serena-ruan
reviewed
Dec 19, 2025
| #: Whether to enable authorization for graphQL routes in MLflow server. | ||
| #: (default: ``True``) | ||
| MLFLOW_SERVER_ENABLE_GRAPHQL_AUTH = _BooleanEnvironmentVariable( | ||
| "MLFLOW_SERVER_ENABLE_GRAPHQL_AUTH", True |
Collaborator
There was a problem hiding this comment.
Should we default to False?
Collaborator
Author
There was a problem hiding this comment.
for addressing the CVE, we should make default True. (i.e. the default configure shouldn't have CVE)
Contributor
|
Documentation preview for 7af0dce is available at: More info
|
WeichenXu123
added a commit
to WeichenXu123/mlflow
that referenced
this pull request
Dec 19, 2025
…rization (mlflow#19504) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
WeichenXu123
added a commit
that referenced
this pull request
Dec 19, 2025
…rization (#19504) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🛠 DevTools 🛠
Install mlflow from this PR
For Databricks, use the following command:
Related Issues/PRs
#xxxWhat changes are proposed in this pull request?
Add an env var for controlling whether to enable GraphQL routes authorization
follow-up for #19278 (comment)
How is this PR tested?
Does this PR require documentation update?
Release Notes
Is this a user-facing change?
What component(s), interfaces, languages, and integrations does this PR affect?
Components
area/tracking: Tracking Service, tracking client APIs, autologgingarea/models: MLmodel format, model serialization/deserialization, flavorsarea/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registryarea/scoring: MLflow Model server, model deployment tools, Spark UDFsarea/evaluation: MLflow model evaluation features, evaluation metrics, and evaluation workflowsarea/gateway: MLflow AI Gateway client APIs, server, and third-party integrationsarea/prompts: MLflow prompt engineering features, prompt templates, and prompt managementarea/tracing: MLflow Tracing features, tracing APIs, and LLM tracing functionalityarea/projects: MLproject format, project running backendsarea/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev serverarea/build: Build and test infrastructure for MLflowarea/docs: MLflow documentation pagesHow should the PR be classified in the release notes? Choose one:
rn/none- No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" sectionrn/breaking-change- The PR will be mentioned in the "Breaking Changes" sectionrn/feature- A new user-facing feature worth mentioning in the release notesrn/bug-fix- A user-facing bug fix worth mentioning in the release notesrn/documentation- A user-facing documentation change worth mentioning in the release notesShould this PR be included in the next patch release?
Yesshould be selected for bug fixes, documentation updates, and other small changes.Noshould be selected for new features and larger changes. If you're unsure about the release classification of this PR, leave this unchecked to let the maintainers decide.What is a minor/patch release?
Bug fixes, doc updates and new features usually go into minor releases.
Bug fixes and doc updates usually go into patch releases.