codeant-ai-for-open-source[bot] commented on code in PR #44307:
URL: https://github.com/apache/superset/pull/44307#discussion_r4015433158
##########
superset/commands/dashboard/importers/v1/__init__.py:
##########
@@ -75,6 +75,48 @@ def __init__(self, contents: dict[str, str], *args: Any,
**kwargs: Any) -> None:
self.overwrite_all = kwargs.pop("overwrite_all", False)
super().__init__(contents, *args, **kwargs)
+ def _prevent_overwrite_existing_model( # pylint: disable=invalid-name
+ self, exceptions: list[ValidationError]
+ ) -> None:
+ """Dashboards are also identified by ``slug`` on import.
+
+ ``import_dashboard()`` resolves a config carrying a fresh UUID but a
+ slug owned by an existing *active* dashboard onto that row, so the
+ overwrite gate must treat that collision like a UUID match: without
+ ``overwrite`` the import would silently merge the bundle's charts
+ into the slug-owning dashboard, and with ``overwrite`` it would
+ replace a dashboard the user never saw in the confirmation prompt
+ (which lists files, not UUIDs). The message matches the UUID branch
+ verbatim so the ImportModal's ``already exists`` detection keeps
+ working; soft-deleted owners are left to the restore path.
+ """
+ super()._prevent_overwrite_existing_model(exceptions)
+ if self.overwrite:
+ return
+ for file_name, config in self._configs.items():
+ slug = config.get("slug")
+ if not slug or not file_name.startswith(self.prefix):
+ continue
Review Comment:
**Suggestion:** `slug=""` is skipped, but the import path treats empty
strings as identity values, so an active empty-slug dashboard can still receive
the incoming dashboard's charts without overwrite confirmation. [incorrect
condition logic]
**Assessment:** ๐ `Major` ยท ๐ `Occurrence: Rarely`
[](https://docs.codeant.ai/cli/resolve-pr-comments-skill)
[](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=98674e2c97934b2c99acbbdd71a74c7a&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
[](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=98674e2c97934b2c99acbbdd71a74c7a&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
<details>
<summary><b>Prompt for AI Agent ๐ค </b></summary>
```mdx
This is a comment left during a code review.
**Path:** superset/commands/dashboard/importers/v1/__init__.py
**Line:** 98:99
**Comment:**
*Incorrect Condition Logic: `slug=""` is skipped, but the import path
treats empty strings as identity values, so an active empty-slug dashboard can
still receive the incoming dashboard's charts without overwrite confirmation.
Validate the correctness of the flagged issue. If correct, How can I resolve
this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask
user if the user wants to fix the rest of the comments as well. if said yes,
then fetch all the comments validate the correctness and implement a minimal fix
```
</details>
<a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44307&comment_hash=f4494fd5ba33988f4e261fe90841df50c5626b68a07978ff16e0024e3b4273c4&reaction=like'>๐</a>
| <a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44307&comment_hash=f4494fd5ba33988f4e261fe90841df50c5626b68a07978ff16e0024e3b4273c4&reaction=dislike'>๐</a>
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]