AmoghAtreya commented on code in PR #44968:
URL: https://github.com/apache/superset/pull/44968#discussion_r4180654661
##########
superset/mcp_service/sql_lab/tool/execute_sql.py:
##########
@@ -210,12 +248,17 @@ async def execute_sql(request: ExecuteSqlRequest, ctx:
Context) -> ExecuteSqlRes
await ctx.error("Query could not be parsed for access
validation")
return _invalid_sql_response()
+ rendered_sql = await _authorize_rendered_sql(
Review Comment:
Just took a look at this and I believe that Bito is incorrect about the
redundancy being unnecessary here. The two checks authorize different SQL,
making the double authorization valid. `raise_for_access` renders through
`process_jinja_sql`, which neutralizes partition macros before parsing.
`_authorize_rendered_sql` renders with `process_template`, the renderer
execution uses and authorizes that literal string. Those renders can name
different tables, so the second check is what gates the SQL that actually runs.
The first check stays so a denied query does not get its live macros evaluated.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]