aminghadersohi commented on code in PR #41472: URL: https://github.com/apache/superset/pull/41472#discussion_r3493608876
########## superset/mcp_service/chart/tool/delete_chart.py: ########## @@ -0,0 +1,140 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +""" +MCP tool: delete_chart +""" + +import logging + +from fastmcp import Context +from sqlalchemy.exc import SQLAlchemyError +from superset_core.mcp.decorators import tool, ToolAnnotations + +from superset.commands.chart.exceptions import ( + ChartDeleteFailedReportsExistError, + ChartForbiddenError, + ChartNotFoundError, +) +from superset.commands.exceptions import CommandException +from superset.extensions import event_logger +from superset.mcp_service.chart.chart_helpers import find_chart_by_identifier +from superset.mcp_service.chart.schemas import ( + DeleteChartRequest, + DeleteChartResponse, +) +from superset.mcp_service.utils import escape_llm_context_delimiters + +logger = logging.getLogger(__name__) + + +def _rollback() -> None: + from superset import db + + try: + db.session.rollback() # pylint: disable=consider-using-transaction + except SQLAlchemyError: + logger.warning("Database rollback failed during delete_chart error handling") + + +@tool( + tags=["mutate"], + class_permission_name="Chart", + annotations=ToolAnnotations( + title="Delete chart", + readOnlyHint=False, + destructiveHint=True, + ), +) +async def delete_chart( + request: DeleteChartRequest, ctx: Context +) -> DeleteChartResponse: + """Permanently delete a saved chart. + + Identify the chart by numeric ID or UUID string (NOT chart name). This is + destructive and cannot be undone. The caller must own the chart (or be an + Admin); charts with attached alerts/reports cannot be deleted until those + are removed. + + Example: + ```json + {"identifier": 123} + ``` + + Returns success with the deleted chart's id/name, or an error. When the + caller lacks permission, ``permission_denied`` is true — do not retry; ask + the user. + """ + await ctx.info("Deleting chart: identifier=%s" % (request.identifier,)) + + chart = find_chart_by_identifier(request.identifier) + if not chart: + safe_id = escape_llm_context_delimiters(str(request.identifier)[:200]) + msg = ( + f"No chart found with identifier: {safe_id}. " + "Use list_charts to get valid chart IDs." + ) + return DeleteChartResponse(success=False, error=msg, error_type="NotFound") + + chart_id = chart.id + chart_name = chart.slice_name + + try: + from superset.commands.chart.delete import DeleteChartCommand + + with event_logger.log_context(action="mcp.delete_chart"): Review Comment: **MEDIUM — Audit gap: failed delete attempts are not recorded** `event_logger.log_context` is a `@contextmanager` with no `try/finally` around its `yield`. If `DeleteChartCommand([chart_id]).run()` raises any exception — `ChartForbiddenError`, `ChartDeleteFailedReportsExistError`, `ChartNotFoundError`, or anything in the generic handler — the `log_with_context` call after the `yield` is never reached. Only successful deletions appear in the event audit log. For a destructive tool invokable by an AI agent, unauthorized deletion _attempts_ are exactly the events you need in the audit trail (CC7.2). Suggested fix — wrap with try/finally so the action is recorded regardless of outcome: ```python with event_logger.log_context(action="mcp.delete_chart") as log: try: DeleteChartCommand([chart_id]).run() except Exception: log(success=False) raise log(success=True) ``` Or call `event_logger.log_with_context` explicitly in each exception handler. Same issue applies to `delete_dashboard.py:120`. ########## superset/mcp_service/chart/tool/delete_chart.py: ########## @@ -0,0 +1,140 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +""" +MCP tool: delete_chart +""" + +import logging + +from fastmcp import Context +from sqlalchemy.exc import SQLAlchemyError +from superset_core.mcp.decorators import tool, ToolAnnotations + +from superset.commands.chart.exceptions import ( + ChartDeleteFailedReportsExistError, + ChartForbiddenError, + ChartNotFoundError, +) +from superset.commands.exceptions import CommandException +from superset.extensions import event_logger +from superset.mcp_service.chart.chart_helpers import find_chart_by_identifier +from superset.mcp_service.chart.schemas import ( + DeleteChartRequest, + DeleteChartResponse, +) +from superset.mcp_service.utils import escape_llm_context_delimiters + +logger = logging.getLogger(__name__) + + +def _rollback() -> None: + from superset import db + + try: + db.session.rollback() # pylint: disable=consider-using-transaction + except SQLAlchemyError: + logger.warning("Database rollback failed during delete_chart error handling") + + +@tool( + tags=["mutate"], + class_permission_name="Chart", + annotations=ToolAnnotations( + title="Delete chart", + readOnlyHint=False, + destructiveHint=True, + ), +) +async def delete_chart( + request: DeleteChartRequest, ctx: Context +) -> DeleteChartResponse: + """Permanently delete a saved chart. + + Identify the chart by numeric ID or UUID string (NOT chart name). This is + destructive and cannot be undone. The caller must own the chart (or be an + Admin); charts with attached alerts/reports cannot be deleted until those + are removed. + + Example: + ```json + {"identifier": 123} + ``` + + Returns success with the deleted chart's id/name, or an error. When the + caller lacks permission, ``permission_denied`` is true — do not retry; ask + the user. + """ + await ctx.info("Deleting chart: identifier=%s" % (request.identifier,)) + + chart = find_chart_by_identifier(request.identifier) + if not chart: + safe_id = escape_llm_context_delimiters(str(request.identifier)[:200]) + msg = ( + f"No chart found with identifier: {safe_id}. " + "Use list_charts to get valid chart IDs." + ) + return DeleteChartResponse(success=False, error=msg, error_type="NotFound") + + chart_id = chart.id + chart_name = chart.slice_name + + try: + from superset.commands.chart.delete import DeleteChartCommand + + with event_logger.log_context(action="mcp.delete_chart"): + DeleteChartCommand([chart_id]).run() + + return DeleteChartResponse( + success=True, + deleted_id=chart_id, + deleted_name=chart_name, + message=f"Deleted chart '{chart_name}' (id={chart_id}).", + ) + except ChartForbiddenError: + await ctx.warning("Permission denied deleting chart id=%s" % (chart_id,)) + return DeleteChartResponse( + success=False, + permission_denied=True, + error=( + f"You do not have permission to delete chart '{chart_name}' " + f"(id={chart_id}). Ask the user to delete it or grant access; " + "do not retry." + ), + error_type="Forbidden", + ) + except ChartDeleteFailedReportsExistError as ex: + _rollback() + return DeleteChartResponse( + success=False, + error=( + f"Chart '{chart_name}' (id={chart_id}) cannot be deleted: {ex}. " + "Remove the associated alerts/reports first." + ), + error_type="ReportsExist", + ) + except ChartNotFoundError: + msg = f"Chart id={chart_id} no longer exists." + return DeleteChartResponse(success=False, error=msg, error_type="NotFound") + except (CommandException, SQLAlchemyError, ValueError) as ex: + _rollback() + await ctx.error("Chart delete failed: %s: %s" % (type(ex).__name__, ex)) + return DeleteChartResponse( + success=False, + error=f"Chart delete failed: {ex}", Review Comment: **MEDIUM — `str(SQLAlchemyError)` returned to the LLM** The generic handler returns `error=f"Chart delete failed: {ex}"`. If `ex` is a raw `SQLAlchemyError` (possible: the except clause explicitly lists it), `str(ex)` can include the raw SQL statement, table/column names, constraint names, and DB error codes — all of which are DB-schema details that should not reach the LLM context. In the normal path `@transaction` wraps `SQLAlchemyError` as `ChartDeleteFailedError()` (no message), so this is less likely to trigger in practice. But the `except SQLAlchemyError` clause signals you're anticipating it, and if it fires the full DB error goes to the agent. Suggested fix: ```python except (CommandException, SQLAlchemyError, ValueError) as ex: _rollback() await ctx.error("Chart delete failed: %s: %s" % (type(ex).__name__, ex)) return DeleteChartResponse( success=False, error="Chart delete failed due to a server error.", # no str(ex) here error_type=type(ex).__name__, ) ``` Same pattern applies to `delete_dashboard.py:164`. ########## tests/unit_tests/mcp_service/chart/tool/test_delete_chart.py: ########## @@ -0,0 +1,131 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +"""Unit tests for the delete_chart MCP tool. + +Run through the async MCP Client (not direct calls); auth is mocked via the +autouse mock_auth fixture, matching the other chart tool test files. +""" + +from unittest.mock import Mock, patch + +import pytest +from fastmcp import Client + +from superset.mcp_service.app import mcp + + [email protected] +def mcp_server() -> object: + return mcp + + [email protected](autouse=True) +def mock_auth(): + with patch("superset.mcp_service.auth.get_user_from_request") as mock_get_user: + mock_user = Mock() + mock_user.id = 1 + mock_user.username = "admin" + mock_get_user.return_value = mock_user + yield mock_get_user + + +def _mock_chart(chart_id: int = 10, slice_name: str = "Test Chart") -> Mock: + chart = Mock() + chart.id = chart_id + chart.slice_name = slice_name + return chart + + +@patch("superset.mcp_service.chart.tool.delete_chart.find_chart_by_identifier") [email protected] +async def test_delete_chart_not_found(mock_find: Mock, mcp_server: object) -> None: + mock_find.return_value = None + + async with Client(mcp_server) as client: + result = await client.call_tool( + "delete_chart", {"request": {"identifier": 999}} + ) + + content = result.structured_content + assert content["success"] is False + assert content["error_type"] == "NotFound" + assert "999" in (content["error"] or "") + + +@patch("superset.commands.chart.delete.DeleteChartCommand.run") +@patch("superset.mcp_service.chart.tool.delete_chart.find_chart_by_identifier") [email protected] +async def test_delete_chart_success( + mock_find: Mock, mock_run: Mock, mcp_server: object +) -> None: + mock_find.return_value = _mock_chart(chart_id=10, slice_name="Sales") + mock_run.return_value = None + + async with Client(mcp_server) as client: + result = await client.call_tool("delete_chart", {"request": {"identifier": 10}}) + + content = result.structured_content + assert content["success"] is True + assert content["deleted_id"] == 10 Review Comment: **MEDIUM — Generic error handler is untested** The `except (CommandException, SQLAlchemyError, ValueError)` branch in `delete_chart.py:133` has no test. This is the only path that exercises `error=f"Chart delete failed: {ex}"` (the potential info-exposure line). Add a test that patches `DeleteChartCommand.run` to raise `CommandException` and asserts: - `success is False` - `permission_denied is False` - `error` does not contain raw DB internals Same gap exists in `test_delete_dashboard.py`. ########## superset/mcp_service/dashboard/tool/delete_dashboard.py: ########## @@ -0,0 +1,166 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +""" +MCP tool: delete_dashboard +""" + +import logging +from typing import Any + +from fastmcp import Context +from sqlalchemy.exc import SQLAlchemyError +from superset_core.mcp.decorators import tool, ToolAnnotations + +from superset.commands.dashboard.exceptions import ( + DashboardDeleteFailedReportsExistError, + DashboardForbiddenError, + DashboardNotFoundError, +) +from superset.commands.exceptions import CommandException +from superset.extensions import event_logger +from superset.mcp_service.dashboard.schemas import ( + DeleteDashboardRequest, + DeleteDashboardResponse, +) +from superset.mcp_service.utils import escape_llm_context_delimiters + +logger = logging.getLogger(__name__) + + +def _find_dashboard_by_identifier(identifier: int | str) -> Any | None: + """Resolve a dashboard by numeric ID, UUID string, or slug. Returns None.""" + from superset.daos.dashboard import DashboardDAO + + if isinstance(identifier, int) or ( + isinstance(identifier, str) and identifier.isdigit() + ): + return DashboardDAO.find_by_id(int(identifier)) + # Try UUID, then fall back to slug. + dashboard = DashboardDAO.find_by_id(identifier, id_column="uuid") + if dashboard: + return dashboard + try: + return DashboardDAO.get_by_id_or_slug(identifier) + except DashboardNotFoundError: + return None + + +def _rollback() -> None: + from superset import db + + try: + db.session.rollback() # pylint: disable=consider-using-transaction + except SQLAlchemyError: + logger.warning( + "Database rollback failed during delete_dashboard error handling" + ) + + +@tool( + tags=["mutate"], + class_permission_name="Dashboard", + annotations=ToolAnnotations( + title="Delete dashboard", + readOnlyHint=False, + destructiveHint=True, + ), +) +async def delete_dashboard( + request: DeleteDashboardRequest, ctx: Context +) -> DeleteDashboardResponse: + """Permanently delete a dashboard. + + Identify the dashboard by numeric ID, UUID string, or slug. This is + destructive and cannot be undone. It removes the dashboard container only — + the charts on it are NOT deleted. The caller must own the dashboard (or be + an Admin); dashboards with attached alerts/reports cannot be deleted until + those are removed. + + Example: + ```json + {"identifier": 42} + ``` + + Returns success with the deleted dashboard's id/title, or an error. When the + caller lacks permission, ``permission_denied`` is true — do not retry; ask + the user. + """ + await ctx.info("Deleting dashboard: identifier=%s" % (request.identifier,)) + + dashboard = _find_dashboard_by_identifier(request.identifier) + if not dashboard: + safe_id = escape_llm_context_delimiters(str(request.identifier)[:200]) + msg = ( + f"No dashboard found with identifier: {safe_id}. " + "Use list_dashboards to get valid dashboard IDs." + ) + return DeleteDashboardResponse(success=False, error=msg, error_type="NotFound") + + dashboard_id = dashboard.id + dashboard_name = dashboard.dashboard_title + + try: + from superset.commands.dashboard.delete import DeleteDashboardCommand + + with event_logger.log_context(action="mcp.delete_dashboard"): Review Comment: **MEDIUM — Audit gap (same as `delete_chart.py:99`)** `event_logger.log_context` does not log on exception. Failed dashboard deletion attempts — forbidden, blocked-by-reports, not-found — are not recorded in the event audit log. Apply the same fix described on `delete_chart.py:99`. ########## superset/mcp_service/dashboard/tool/delete_dashboard.py: ########## @@ -0,0 +1,166 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +""" +MCP tool: delete_dashboard +""" + +import logging +from typing import Any + +from fastmcp import Context +from sqlalchemy.exc import SQLAlchemyError +from superset_core.mcp.decorators import tool, ToolAnnotations + +from superset.commands.dashboard.exceptions import ( + DashboardDeleteFailedReportsExistError, + DashboardForbiddenError, + DashboardNotFoundError, +) +from superset.commands.exceptions import CommandException +from superset.extensions import event_logger +from superset.mcp_service.dashboard.schemas import ( + DeleteDashboardRequest, + DeleteDashboardResponse, +) +from superset.mcp_service.utils import escape_llm_context_delimiters + +logger = logging.getLogger(__name__) + + +def _find_dashboard_by_identifier(identifier: int | str) -> Any | None: + """Resolve a dashboard by numeric ID, UUID string, or slug. Returns None.""" + from superset.daos.dashboard import DashboardDAO + + if isinstance(identifier, int) or ( + isinstance(identifier, str) and identifier.isdigit() + ): + return DashboardDAO.find_by_id(int(identifier)) + # Try UUID, then fall back to slug. + dashboard = DashboardDAO.find_by_id(identifier, id_column="uuid") + if dashboard: + return dashboard + try: + return DashboardDAO.get_by_id_or_slug(identifier) + except DashboardNotFoundError: + return None + + +def _rollback() -> None: + from superset import db + + try: + db.session.rollback() # pylint: disable=consider-using-transaction + except SQLAlchemyError: + logger.warning( + "Database rollback failed during delete_dashboard error handling" + ) + + +@tool( + tags=["mutate"], + class_permission_name="Dashboard", + annotations=ToolAnnotations( + title="Delete dashboard", + readOnlyHint=False, + destructiveHint=True, + ), +) +async def delete_dashboard( + request: DeleteDashboardRequest, ctx: Context +) -> DeleteDashboardResponse: + """Permanently delete a dashboard. + + Identify the dashboard by numeric ID, UUID string, or slug. This is + destructive and cannot be undone. It removes the dashboard container only — + the charts on it are NOT deleted. The caller must own the dashboard (or be + an Admin); dashboards with attached alerts/reports cannot be deleted until + those are removed. + + Example: + ```json + {"identifier": 42} + ``` + + Returns success with the deleted dashboard's id/title, or an error. When the + caller lacks permission, ``permission_denied`` is true — do not retry; ask + the user. + """ + await ctx.info("Deleting dashboard: identifier=%s" % (request.identifier,)) + + dashboard = _find_dashboard_by_identifier(request.identifier) + if not dashboard: + safe_id = escape_llm_context_delimiters(str(request.identifier)[:200]) + msg = ( + f"No dashboard found with identifier: {safe_id}. " + "Use list_dashboards to get valid dashboard IDs." + ) + return DeleteDashboardResponse(success=False, error=msg, error_type="NotFound") + + dashboard_id = dashboard.id + dashboard_name = dashboard.dashboard_title + + try: + from superset.commands.dashboard.delete import DeleteDashboardCommand + + with event_logger.log_context(action="mcp.delete_dashboard"): + DeleteDashboardCommand([dashboard_id]).run() + + return DeleteDashboardResponse( + success=True, + deleted_id=dashboard_id, + deleted_name=dashboard_name, + message=( + f"Deleted dashboard '{dashboard_name}' (id={dashboard_id}). " + "Its charts were not deleted." + ), + ) + except DashboardForbiddenError: + await ctx.warning( + "Permission denied deleting dashboard id=%s" % (dashboard_id,) + ) + return DeleteDashboardResponse( + success=False, + permission_denied=True, + error=( + f"You do not have permission to delete dashboard " + f"'{dashboard_name}' (id={dashboard_id}). Ask the user to delete " + "it or grant access; do not retry." + ), + error_type="Forbidden", + ) + except DashboardDeleteFailedReportsExistError as ex: + _rollback() + return DeleteDashboardResponse( + success=False, + error=( + f"Dashboard '{dashboard_name}' (id={dashboard_id}) cannot be " + f"deleted: {ex}. Remove the associated alerts/reports first." + ), + error_type="ReportsExist", + ) + except DashboardNotFoundError: + msg = f"Dashboard id={dashboard_id} no longer exists." + return DeleteDashboardResponse(success=False, error=msg, error_type="NotFound") + except (CommandException, SQLAlchemyError, ValueError) as ex: + _rollback() + await ctx.error("Dashboard delete failed: %s: %s" % (type(ex).__name__, ex)) + return DeleteDashboardResponse( + success=False, + error=f"Dashboard delete failed: {ex}", Review Comment: **MEDIUM — `str(SQLAlchemyError)` returned to the LLM (same as `delete_chart.py:138`)** `error=f"Dashboard delete failed: {ex}"` passes the raw exception string to the LLM. Apply the same sanitisation fix described on `delete_chart.py:138`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
