Vitor-Avila commented on issue #37364: URL: https://github.com/apache/superset/issues/37364#issuecomment-3813429751
I agree with @Kash-ish15 here, would love to get more context on the requirement. Ideally your `/guest-token-rls` endpoint should not accept a `filter_value` as a URL parameter, as the user could forge a request passing another parameter to see different results. The decision of which filter/RLS to apply should be defined at the backend side, based on the user interacting with the endpoint. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
