I3eka commented on code in PR #43237:
URL: https://github.com/apache/superset/pull/43237#discussion_r4112728865


##########
superset/ai/page_context.py:
##########
@@ -0,0 +1,372 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#   http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+"""
+What the user is looking at, rendered for the model.
+
+This is what lets someone ask "why is this number lower than last week?" while
+looking at a dashboard and get an answer about *that* chart. Without it the
+assistant is a search box that happens to live in Superset.
+
+The client gathers the context — it is the only party that knows which tab is
+open, what is typed in the editor, and which filters are applied — and this
+module turns it into prose. Everything here is treated as untrusted: a 
dashboard
+title, a chart description or a markdown block is authored by a user, so it is
+data and never instruction.
+"""
+
+from __future__ import annotations
+
+from typing import Any
+
+#: Ceiling on the whole rendered block. Page context competes with conversation
+#: history for the same budget, so an enormous dashboard cannot crowd out the
+#: question being asked.
+MAX_CONTEXT_CHARS = 20_000
+
+#: Ceiling on the editor SQL specifically. A pasted migration script should not
+#: consume the entire context, and the useful part is near the top.
+MAX_SQL_CHARS = 10_000
+
+#: Markdown authored on a dashboard is how a team explains its own data, so it
+#: is worth real space — but bounded, and only a handful of blocks.
+MAX_MARKDOWN_BLOCKS = 10
+MAX_MARKDOWN_BLOCK_CHARS = 4_000
+
+#: Lists that could otherwise be unbounded.
+MAX_CHARTS = 50
+MAX_FILTERS = 25
+MAX_TABLES = 20
+
+#: Page types the client may report. An unknown value renders as "other" rather
+#: than being echoed back into the prompt.
+KNOWN_PAGE_TYPES = frozenset(
+    {"sqllab", "explore", "dashboard", "chart", "home", "other"}
+)
+
+
+def render_page_context(context: Any) -> str:
+    """
+    Render the client's page context as a prompt section.
+
+    Returns an empty string when there is nothing useful, so the caller can
+    append unconditionally. Never raises: a malformed payload from a stale
+    client costs the model some context, and should not cost the user an 
answer.
+    """
+    if not isinstance(context, dict):
+        return ""
+
+    try:
+        return _render(context)[:MAX_CONTEXT_CHARS]
+    except Exception:  # pylint: disable=broad-except

Review Comment:
   Confirmed independently and fixed in #44717. The same three-file patch is 
imported here as `41b0ac8a83` with an identical stable patch ID. The renderer 
reuses `sanitize_for_llm_context` for every rendered client-text path, 
including SQL, Markdown, filter values, chart controls and path/table names; 
allowlisted page types and validated numeric IDs remain usable as tool 
arguments.
   
   The extra edge case was truncation: framing first and slicing afterward 
could remove a closing delimiter. Field limits now run before framing, and the 
whole section stops at complete rendered entries. Five added cases fail on the 
unchanged shared base and pass with the fix. This target branch passes **722 AI 
tests** and all applicable hooks on its **113 PR files**; the original 
structured-truncation code/tests are unchanged.
   
   This establishes consistent prompt framing, not an authorization boundary or 
proof that a model can never follow malicious text. Structured input 
validation/persistence and the separately documented 
migration/translation/formatter CI failures are not fixed by this patch.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to