codeant-ai-for-open-source[bot] commented on code in PR #44626:
URL: https://github.com/apache/superset/pull/44626#discussion_r4099902102


##########
superset/security/password_change.py:
##########
@@ -42,25 +44,31 @@
 # Flask endpoints take the form ``<ViewClass>.<method>`` (or a bare name for
 # function views). The following must remain reachable while a password change
 # is pending, otherwise the redirect would loop: the auth views (login/logout
-# for every auth backend), the password-reset and user-info-edit views, static
-# assets, and the health blueprint. We match the *view-class* component (the 
part
-# before the dot) exactly against the allow-list below rather than doing a
-# substring search, so unrelated endpoints that merely share a substring (e.g.
-# an "Author"-named view, or any name containing "health"/"static") are not
-# accidentally exempted from enforcement.
+# for every auth backend), the SPA profile page and the APIs its password
+# change modal needs (the current-user API it submits to and the CSRF token
+# endpoint), the legacy user-info-edit view, static assets, and the health
+# blueprint. We match the *view-class* component (the part before the dot)
+# exactly against the allow-list below rather than doing a substring search, so
+# unrelated endpoints that merely share a substring (e.g. an "Author"-named
+# view, or any name containing "health"/"static") are not accidentally exempted
+# from enforcement.
 _EXEMPT_VIEW_CLASSES = frozenset(
     {
         "AuthDBView",
         "AuthLDAPView",
         "AuthOAuthView",
         "AuthOIDView",
         "AuthRemoteUserView",
-        "ResetMyPasswordView",
-        "ResetPasswordView",
+        "CurrentUserRestApi",
+        "SecurityRestApi",

Review Comment:
   **Suggestion:** Exempting all `SecurityRestApi` endpoints lets flagged users 
call `guest_token` when they have its permission, bypassing the intended 
profile-page-only restriction.
   
   **Assessment:** ๐ŸŸ  `Major` ยท ๐Ÿ” `Occurrence: Rarely` ยท ๐Ÿท๏ธ `Security`
   
   [![Use CodeAnt 
Skill](https://new-codeant-butcket.s3.us-west-1.amazonaws.com/badges/use-codeant-skill-flat-v2.svg)](https://docs.codeant.ai/cli/resolve-pr-comments-skill)
 [![Fix in 
Cursor](https://new-codeant-butcket.s3.us-west-1.amazonaws.com/badges/fix-in-cursor-flat.svg)](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=a2c83a4d311b40f1bc4e8f45558d11e8&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
 [![Fix in VSCode 
Claude](https://new-codeant-butcket.s3.us-west-1.amazonaws.com/badges/fix-in-vscode-claude-flat.svg)](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=a2c83a4d311b40f1bc4e8f45558d11e8&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
   <details>
   <summary><b>Prompt for AI Agent ๐Ÿค– </b></summary>
   
   ```mdx
   This is a comment left during a code review.
   
   **Path:** superset/security/password_change.py
   **Line:** 63:63
   **Comment:**
        *Security: Exempting all `SecurityRestApi` endpoints lets flagged users 
call `guest_token` when they have its permission, bypassing the intended 
profile-page-only restriction.
   
   Validate the correctness of the flagged issue. If correct, How can I resolve 
this? If you propose a fix, implement it and please make it concise.
   Once fix is implemented, also check other comments on the same PR, and ask 
user if the user wants to fix the rest of the comments as well. if said yes, 
then fetch all the comments validate the correctness and implement a minimal fix
   ```
   </details>
   <a 
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44626&comment_hash=08da12ce2c37de93bb9761140281e41228af679cd5be087beb84e9a6b07dc44e&reaction=like'>๐Ÿ‘</a>
 | <a 
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44626&comment_hash=08da12ce2c37de93bb9761140281e41228af679cd5be087beb84e9a6b07dc44e&reaction=dislike'>๐Ÿ‘Ž</a>



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to