mikebridge opened a new pull request, #44987:
URL: https://github.com/apache/superset/pull/44987

   ### SUMMARY
   
   Row-level security is not supported for semantic views in the MVP. Embedded 
requests whose guest token carries an applicable RLS rule (a global rule, or 
one scoped to the semantic view) are now refused with a clear error ("Semantic 
views cannot enforce guest row-level security rules.") instead of being served. 
This applies to semantic chart queries and their cached results, column-value 
suggestions, and the MCP `get_table` tool.
   
   Semantic views with no applicable guest rule are unaffected. SQL dataset 
queries continue to enforce their applicable guest rules as before; a chart 
that also requests semantic content (for example a semantic-backed annotation 
layer) is subject to the semantic-view restriction for that content. The 
embedding docs describe the restriction.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A (backend).
   
   ### TESTING INSTRUCTIONS
   
   - `pytest tests/unit_tests/security/semantic_guest_rls_test.py 
tests/unit_tests/mcp_service/semantic_layer/tool/test_get_table.py`
   - Covers: global guest rules and rules scoped to the semantic view are 
refused for execution, cached reads, the values endpoint and MCP `get_table`; 
guests without an applicable rule and non-guest users are unaffected; SQL 
datasets still apply guest RLS.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [x] Required feature flags: `SEMANTIC_LAYERS`, and `EMBEDDED_SUPERSET` for 
the embedded path
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to