aminghadersohi commented on code in PR #44987:
URL: https://github.com/apache/superset/pull/44987#discussion_r4187265602
##########
superset/common/query_context_processor.py:
##########
@@ -428,7 +428,9 @@ def query_cache_key(self, query_obj: QueryObject, **kwargs:
Any) -> str | None:
"""
Returns a QueryObject cache key for objects in self.queries
"""
- datasource = self._qc_datasource
+ datasource: Explorable = self._qc_datasource
+ # Reject unenforceable restrictions before provider identity or cache
reads.
+ rls: list[str] = security_manager.get_rls_cache_key(datasource)
Review Comment:
`SemanticView.get_extra_cache_keys` returns `[]`, so this hoist has no
observable effect at this head; moving the call back below it passes all 1682
tests in the touched suites. To lock the ordering, give `get_extra_cache_keys`
an AssertionError side_effect in the cached-read test.
##########
docs/docs/using-superset/embedding.mdx:
##########
@@ -163,7 +163,7 @@ One caveat when the host page lives on a different site
than Superset: the defau
## Security Notes
- **Guest tokens expire** — their lifetime is controlled by the
`GUEST_TOKEN_JWT_EXP_SECONDS` config (default: 5 minutes). Refresh tokens
before they expire using a token refresh mechanism in your host app.
-- **Row-level security** — pass `rls` rules in the guest token request to
restrict which rows are visible to the embedded user.
+- **Row-level security** — pass `rls` rules in the guest token request to
restrict which rows are visible to the embedded user. Semantic views cannot
enforce guest-token SQL clauses, so queries and cached-result reads are
rejected when a global rule or a rule scoped to the semantic view applies. Read
permissions do not override these restrictions. Semantic views remain
accessible when no guest rule applies; SQL datasets continue to enforce their
applicable rules.
Review Comment:
Guest `rls` rules carry only a bare `dataset` integer, and SQL datasets and
semantic views have separate ID spaces, so a rule meant for SQL dataset 7 also
refuses semantic view 7. A single global rule also refuses every semantic view.
Both fail closed, but worth stating here for hosts.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]