sadpandajoe commented on code in PR #44968:
URL: https://github.com/apache/superset/pull/44968#discussion_r4179273388
##########
superset/sqllab/validators.py:
##########
@@ -33,5 +34,5 @@ def validate(
security_manager.raise_for_access(
query=query,
template_params=template_params,
- force_dataset_match=True,
+ force_dataset_match=requires_dataset_match(),
Review Comment:
With this flag disabled, a user granted only `tenant_a` can submit `USE
tenant_b; SELECT * FROM orders`: authorization checks `tenant_a.orders`, but
the shared execution cursor reads `tenant_b.orders`. Could the schema-rebinding
safeguard remain enforced independently of dataset matching, with a regression
test that this out-of-grant query is denied when the flag is off?
##########
docs/admin_docs/security/security.mdx:
##########
@@ -61,6 +61,16 @@ Beyond the base `sql_lab` role, two additional SQL Lab
permissions must be expli
Grant these in **Security → List Roles** by adding the permissions to the
relevant role.
+Running a query also needs a data grant. By default
(`SQLLAB_REQUIRE_DATASET_MATCH = True`), every table the SQL references must be
a registered dataset the user has `datasource_access` on (or owns).
`database_access` still authorizes the whole database. `schema_access` and
`catalog_access` let the user browse that schema in SQL Lab and still authorize
charts, but they do not authorize query execution.
+
+Set the following in `superset_config.py` when schema- or catalog-wide SQL Lab
access is the intended control (for example, access is managed on the warehouse
and tables change often):
+
+```python
+SQLLAB_REQUIRE_DATASET_MATCH = False
+```
+
+A `schema_access` or `catalog_access` grant then authorizes SQL Lab queries
against every table in that schema, including tables that are not registered as
datasets. The same flag covers result fetch, CSV and streaming export, cost
estimates, SQL formatting, and the MCP `execute_sql` tool. Chart and Explore
access are unchanged. Reports, alerts, MetaDB, and SQL validation still require
a dataset match.
Review Comment:
Agreed—`catalog_access` permits tables across every schema in the granted
catalog, so this understates the access an operator enables. Could the
documentation distinguish catalog-wide access from a single-schema grant?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]