Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Auth] Only admins can create new user #9700

Merged
merged 10 commits into from
Oct 3, 2023

Conversation

gabrielfu
Copy link
Collaborator

@gabrielfu gabrielfu commented Sep 22, 2023

Related Issues/PRs

#9669

What changes are proposed in this pull request?

Only admins are allowed to create new users, to prevent potential attackers from creating lots of users.

How is this patch tested?

  • Existing unit/integration tests
  • New unit/integration tests
  • Manual tests (describe details, including test results, below)

Does this PR require documentation update?

  • No. You can skip the rest of this section.
  • Yes. I've updated:
    • Examples
    • API references
    • Instructions

Release Notes

Is this a user-facing change?

  • No. You can skip the rest of this section.
  • Yes. Give a description of this change to be included in the release notes for MLflow users.

Only admins are allowed to create new users, to prevent potential attackers from creating lots of users.

What component(s), interfaces, languages, and integrations does this PR affect?

Components

  • area/artifacts: Artifact stores and artifact logging
  • area/build: Build and test infrastructure for MLflow
  • area/docs: MLflow documentation pages
  • area/examples: Example code
  • area/gateway: AI Gateway service, Gateway client APIs, third-party Gateway integrations
  • area/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registry
  • area/models: MLmodel format, model serialization/deserialization, flavors
  • area/recipes: Recipes, Recipe APIs, Recipe configs, Recipe Templates
  • area/projects: MLproject format, project running backends
  • area/scoring: MLflow Model server, model deployment tools, Spark UDFs
  • area/server-infra: MLflow Tracking server backend
  • area/tracking: Tracking Service, tracking client APIs, autologging

Interface

  • area/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev server
  • area/docker: Docker use across MLflow's components, such as MLflow Projects and MLflow Models
  • area/sqlalchemy: Use of SQLAlchemy in the Tracking Service or Model Registry
  • area/windows: Windows support

Language

  • language/r: R APIs and clients
  • language/java: Java APIs and clients
  • language/new: Proposals for new client languages

Integrations

  • integrations/azure: Azure and Azure ML integrations
  • integrations/sagemaker: SageMaker integrations
  • integrations/databricks: Databricks integrations

How should the PR be classified in the release notes? Choose one:

  • rn/breaking-change - The PR will be mentioned in the "Breaking Changes" section
  • rn/none - No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" section
  • rn/feature - A new user-facing feature worth mentioning in the release notes
  • rn/bug-fix - A user-facing bug fix worth mentioning in the release notes
  • rn/documentation - A user-facing documentation change worth mentioning in the release notes

Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
@github-actions
Copy link

github-actions bot commented Sep 22, 2023

Documentation preview for 52dd2b3 will be available here when this CircleCI job completes successfully.

More info

@github-actions github-actions bot added area/tracking Tracking service, tracking client APIs, autologging rn/feature Mention under Features in Changelogs. labels Sep 22, 2023
Signed-off-by: Gabriel Fu <[email protected]>
docs/source/auth/index.rst Outdated Show resolved Hide resolved
Co-authored-by: Harutaka Kawamura <[email protected]>
Signed-off-by: Gabriel Fu <[email protected]>
@harupy
Copy link
Member

harupy commented Sep 26, 2023

Do we need to remove the signup form?

@gabrielfu
Copy link
Collaborator Author

@harupy I think it's still helpful if the admin can create users via UI

@harupy
Copy link
Member

harupy commented Sep 27, 2023

@gabrielfu Got it. Is it possible to make the singup page an admin-only page?

@gabrielfu
Copy link
Collaborator Author

@harupy makes sense, let me change it

Copy link
Member

@BenWilson2 BenWilson2 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks for the feature adjustment @gabrielfu ! :)

Copy link
Member

@harupy harupy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/tracking Tracking service, tracking client APIs, autologging rn/feature Mention under Features in Changelogs.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants