Vitor-Avila commented on issue #37364:
URL: https://github.com/apache/superset/issues/37364#issuecomment-3813429751

   I agree with @Kash-ish15 here, would love to get more context on the 
requirement. Ideally your `/guest-token-rls` endpoint should not accept a 
`filter_value` as a URL parameter, as the user could forge a request passing 
another parameter to see different results.
   
   The decision of which filter/RLS to apply should be defined at the backend 
side, based on the user interacting with the endpoint.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to