dosubot[bot] commented on issue #37061:
URL: https://github.com/apache/superset/issues/37061#issuecomment-3739588943

   <!-- Greeting -->
   Hi @HJulio! I'm [Dosu](https://go.dosu.dev/dosubot) and I’m helping the 
superset team.
   
   <!-- Answer -->
   This behavior is intentional in Superset 6.0.0. When a guest user (using a 
guest token in an embedded dashboard) tries to sort a table chart, Superset 
detects this as a modification of the chart's payload—specifically, it changes 
the "orderby" field in the query context. The security logic is designed to 
prevent guest users from modifying the chart payload in any way, including 
sorting, filtering, or changing metrics/columns, to ensure that embedded 
dashboards remain immutable for guests. This restriction is enforced in the 
backend and is not configurable or bypassable via permissions or settings at 
this time. There are no documented workarounds or merged pull requests that 
relax this restriction for guest users in embedded dashboards. If you need 
guest users to be able to sort, you would need to consider a code customization 
or explore alternative embedding strategies with authenticated users instead.  
   [Reference: 
superset/security/manager.py](https://github.com/apache/superset/blob/829e4d92d91ceae4b43b1ed3b063ffe45377799c/superset/security/manager.py#L184-L2731)
   
   
   <!-- Dosu Comment Footer -->
   *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).*
   
   ---
   <sup>How did I do? 
[Good](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=great_response)
 | 
[Irrelevant](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=irrelevant_answer)
 | 
[Incorrect](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=incorrect_sources)
 | 
[Verbose](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=too_verbose)
 | 
[Hallucination](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=hallucination)
 | [Report 
🐛](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=bug_report)
 | 
[Other](https://app.dosu.dev/response-feedback/3cdb539d-6b1c-4ca4-93de-3d2302a619ad?feedback_type=other)</sup>
   
   [![Chat with 
Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/a28d3c7e-a9d3-459e-9fb6-3a6f9ff4f357/ask?utm_source=github)&nbsp;[![Open
 in 
Cursor](https://dosu.dev/dosu-in-cursor.svg)](https://cursor.com/link/prompt?text=This%20behavior%20is%20intentional%20in%20Superset%206.0.0.%20When%20a%20guest%20user%20%28using%20a%20guest%20token%20in%20an%20embedded%20dashboard%29%20tries%20to%20sort%20a%20table%20chart%2C%20Superset%20detects%20this%20as%20a%20modification%20of%20the%20chart%27s%20payload%E2%80%94specifically%2C%20it%20changes%20the%20%22orderby%22%20field%20in%20the%20query%20context.%20The%20security%20logic%20is%20designed%20to%20prevent%20guest%20users%20from%20modifying%20the%20chart%20payload%20in%20any%20way%2C%20including%20sorting%2C%20filtering%2C%20or%20changing%20metrics/columns%2C%20to%20ensure%20that%20embedded%20dashboards%20remain%20immutable%20for%20guests.%20This%20restriction%20is%20enforced%20in%20the%20backend%20and%20is%20not%20configu
 
rable%20or%20bypassable%20via%20permissions%20or%20settings%20at%20this%20time.%20There%20are%20no%20documented%20workarounds%20or%20merged%20pull%20requests%20that%20relax%20this%20restriction%20for%20guest%20users%20in%20embedded%20dashboards.%20If%20you%20need%20guest%20users%20to%20be%20able%20to%20sort%2C%20you%20would%20need%20to%20consider%20a%20code%20customization%20or%20explore%20alternative%20embedding%20strategies%20with%20authenticated%20users%20instead.%20%20%0A%5BReference%3A%20superset/security/manager.py%5D%28https%3A//github.com/apache/superset/blob/829e4d92d91ceae4b43b1ed3b063ffe45377799c/superset/security/manager.py%23L184-L2731%29)&nbsp;[![Join
 
Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share
 on 
X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/apache/superset/issues/37
 061)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to