sadpandajoe commented on code in PR #44968:
URL: https://github.com/apache/superset/pull/44968#discussion_r4179273388


##########
superset/sqllab/validators.py:
##########
@@ -33,5 +34,5 @@ def validate(
         security_manager.raise_for_access(
             query=query,
             template_params=template_params,
-            force_dataset_match=True,
+            force_dataset_match=requires_dataset_match(),

Review Comment:
   With this flag disabled, a user granted only `tenant_a` can submit `USE 
tenant_b; SELECT * FROM orders`: authorization checks `tenant_a.orders`, but 
the shared execution cursor reads `tenant_b.orders`. Could the schema-rebinding 
safeguard remain enforced independently of dataset matching, with a regression 
test that this out-of-grant query is denied when the flag is off?



##########
docs/admin_docs/security/security.mdx:
##########
@@ -61,6 +61,16 @@ Beyond the base `sql_lab` role, two additional SQL Lab 
permissions must be expli
 
 Grant these in **Security → List Roles** by adding the permissions to the 
relevant role.
 
+Running a query also needs a data grant. By default 
(`SQLLAB_REQUIRE_DATASET_MATCH = True`), every table the SQL references must be 
a registered dataset the user has `datasource_access` on (or owns). 
`database_access` still authorizes the whole database. `schema_access` and 
`catalog_access` let the user browse that schema in SQL Lab and still authorize 
charts, but they do not authorize query execution.
+
+Set the following in `superset_config.py` when schema- or catalog-wide SQL Lab 
access is the intended control (for example, access is managed on the warehouse 
and tables change often):
+
+```python
+SQLLAB_REQUIRE_DATASET_MATCH = False
+```
+
+A `schema_access` or `catalog_access` grant then authorizes SQL Lab queries 
against every table in that schema, including tables that are not registered as 
datasets. The same flag covers result fetch, CSV and streaming export, cost 
estimates, SQL formatting, and the MCP `execute_sql` tool. Chart and Explore 
access are unchanged. Reports, alerts, MetaDB, and SQL validation still require 
a dataset match.

Review Comment:
   Agreed—`catalog_access` permits tables across every schema in the granted 
catalog, so this understates the access an operator enables. Could the 
documentation distinguish catalog-wide access from a single-schema grant?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to