Skip to content

Add model version search filtering based on user permissions#20964

Merged
TomeHirata merged 3 commits intomlflow:masterfrom
TomeHirata:fix/auth/search-model-versions
Feb 19, 2026
Merged

Add model version search filtering based on user permissions#20964
TomeHirata merged 3 commits intomlflow:masterfrom
TomeHirata:fix/auth/search-model-versions

Conversation

@TomeHirata
Copy link
Collaborator

Related Issues/PRs

https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08

What changes are proposed in this pull request?

As titled

How is this PR tested?

  • Existing unit/integration tests
  • New unit/integration tests
  • Manual tests

Does this PR require documentation update?

  • No. You can skip the rest of this section.
  • Yes. I've updated:
    • Examples
    • API references
    • Instructions

Does this PR require updating the MLflow Skills repository?

  • No. You can skip the rest of this section.
  • Yes. Please link the corresponding PR or explain how you plan to update it.

Release Notes

Is this a user-facing change?

  • No. You can skip the rest of this section.
  • Yes. Give a description of this change to be included in the release notes for MLflow users.

What component(s), interfaces, languages, and integrations does this PR affect?

Components

  • area/tracking: Tracking Service, tracking client APIs, autologging
  • area/models: MLmodel format, model serialization/deserialization, flavors
  • area/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registry
  • area/scoring: MLflow Model server, model deployment tools, Spark UDFs
  • area/evaluation: MLflow model evaluation features, evaluation metrics, and evaluation workflows
  • area/gateway: MLflow AI Gateway client APIs, server, and third-party integrations
  • area/prompts: MLflow prompt engineering features, prompt templates, and prompt management
  • area/tracing: MLflow Tracing features, tracing APIs, and LLM tracing functionality
  • area/projects: MLproject format, project running backends
  • area/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev server
  • area/build: Build and test infrastructure for MLflow
  • area/docs: MLflow documentation pages

How should the PR be classified in the release notes? Choose one:

  • rn/none - No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" section
  • rn/breaking-change - The PR will be mentioned in the "Breaking Changes" section
  • rn/feature - A new user-facing feature worth mentioning in the release notes
  • rn/bug-fix - A user-facing bug fix worth mentioning in the release notes
  • rn/documentation - A user-facing documentation change worth mentioning in the release notes

Should this PR be included in the next patch release?

Yes should be selected for bug fixes, documentation updates, and other small changes. No should be selected for new features and larger changes. If you're unsure about the release classification of this PR, leave this unchecked to let the maintainers decide.

What is a minor/patch release?
  • Minor release: a release that increments the second part of the version number (e.g., 1.2.0 -> 1.3.0).
    Bug fixes, doc updates and new features usually go into minor releases.
  • Patch release: a release that increments the third part of the version number (e.g., 1.2.0 -> 1.2.1).
    Bug fixes and doc updates usually go into patch releases.
  • Yes (this PR will be cherry-picked and included in the next patch release)
  • No (this PR will be included in the next minor release)

Signed-off-by: Tomu Hirata <tomu.hirata@gmail.com>
Copilot AI review requested due to automatic review settings February 18, 2026 10:31
@github-actions github-actions bot added size/M area/build Build and test infrastructure for MLflow rn/bug-fix Mention under Bug Fixes in Changelogs. labels Feb 18, 2026
@github-actions
Copy link
Contributor

🛠 DevTools 🛠

Install mlflow from this PR

# mlflow
pip install git+https://github.com/mlflow/mlflow.git@refs/pull/20964/merge
# mlflow-skinny
pip install git+https://github.com/mlflow/mlflow.git@refs/pull/20964/merge#subdirectory=libs/skinny

For Databricks, use the following command:

%sh curl -LsSf https://raw.githubusercontent.com/mlflow/mlflow/HEAD/dev/install-skinny.sh | sh -s pull/20964/merge

response_message = SearchModelVersions.Response()
parse_dict(resp.json, response_message)

# fetch permissions
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I intentionally didn't add "re-fetch to fill max results" logic as it increases the complexity and lower the performance. So I think we can start with just filtering and then add the re-fetch if requested.

@TomeHirata TomeHirata added the team-review Trigger a team review request label Feb 18, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds authorization-aware filtering to model version search results so users only see model versions belonging to registered models they can read, aligning model version search with existing permission-based filtering in the auth layer.

Changes:

  • Add after-request filtering for SearchModelVersions responses based on registered model read permissions.
  • Add GraphQL middleware support for mlflowSearchModelVersions with result filtering.
  • Add a unit/integration test covering basic visibility differences between owner vs. a user with READ on a subset of models.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
mlflow/server/auth/__init__.py Adds REST after-request filtering for SearchModelVersions and GraphQL result filtering for mlflowSearchModelVersions.
tests/server/auth/test_auth.py Adds a test validating search_model_versions visibility under different user permissions.

@github-actions
Copy link
Contributor

github-actions bot commented Feb 18, 2026

Documentation preview for 5a1a9e6 is available at:

Changed Pages (1)

More info
  • Ignore this comment if this PR does not change the documentation.
  • The preview is updated when a new commit is pushed to this PR.
  • This comment was created by this workflow run.
  • The documentation was built by this workflow run.

Signed-off-by: Tomu Hirata <tomu.hirata@gmail.com>
return None

return next(root, info, **args)
result = next(root, info, **args)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

interesting, so the graphQL authorization is handled separately from the normal REST auth? out of the scope of this PR but it seems like we should somehow try to merge them as we need to remember to update 2 places now 🤔

Copy link
Collaborator Author

@TomeHirata TomeHirata Feb 19, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

graphQL authorization is handled separately from the normal REST auth?

Yes, this is the current design; agree there should be a way to consolidate them. But for now we don't have many gql resources.

Copy link
Collaborator

@daniellok-db daniellok-db left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lg

Signed-off-by: Tomu Hirata <tomu.hirata@gmail.com>
@TomeHirata TomeHirata enabled auto-merge February 19, 2026 05:38
@TomeHirata TomeHirata added this pull request to the merge queue Feb 19, 2026
Merged via the queue into mlflow:master with commit 6989066 Feb 19, 2026
49 checks passed
@TomeHirata TomeHirata deleted the fix/auth/search-model-versions branch February 19, 2026 06:19
daniellok-db pushed a commit to daniellok-db/mlflow that referenced this pull request Feb 20, 2026
daniellok-db pushed a commit that referenced this pull request Feb 20, 2026
Signed-off-by: Tomu Hirata <tomu.hirata@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/build Build and test infrastructure for MLflow rn/bug-fix Mention under Bug Fixes in Changelogs. size/M team-review Trigger a team review request v3.10.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants