mikebridge opened a new pull request, #44987:
URL: https://github.com/apache/superset/pull/44987
### SUMMARY
Row-level security is not supported for semantic views in the MVP. Embedded
requests whose guest token carries an applicable RLS rule (a global rule, or
one scoped to the semantic view) are now refused with a clear error ("Semantic
views cannot enforce guest row-level security rules.") instead of being served.
This applies to semantic chart queries and their cached results, column-value
suggestions, and the MCP `get_table` tool.
Semantic views with no applicable guest rule are unaffected. SQL dataset
queries continue to enforce their applicable guest rules as before; a chart
that also requests semantic content (for example a semantic-backed annotation
layer) is subject to the semantic-view restriction for that content. The
embedding docs describe the restriction.
### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
N/A (backend).
### TESTING INSTRUCTIONS
- `pytest tests/unit_tests/security/semantic_guest_rls_test.py
tests/unit_tests/mcp_service/semantic_layer/tool/test_get_table.py`
- Covers: global guest rules and rules scoped to the semantic view are
refused for execution, cached reads, the values endpoint and MCP `get_table`;
guests without an applicable rule and non-guest users are unaffected; SQL
datasets still apply guest RLS.
### ADDITIONAL INFORMATION
- [ ] Has associated issue:
- [x] Required feature flags: `SEMANTIC_LAYERS`, and `EMBEDDED_SUPERSET` for
the embedded path
- [ ] Changes UI
- [ ] Includes DB Migration (follow approval process in
[SIP-59](https://github.com/apache/superset/issues/13351))
- [ ] Introduces new feature or API
- [ ] Removes existing feature or API
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]