aminghadersohi commented on code in PR #44987:
URL: https://github.com/apache/superset/pull/44987#discussion_r4187265602


##########
superset/common/query_context_processor.py:
##########
@@ -428,7 +428,9 @@ def query_cache_key(self, query_obj: QueryObject, **kwargs: 
Any) -> str | None:
         """
         Returns a QueryObject cache key for objects in self.queries
         """
-        datasource = self._qc_datasource
+        datasource: Explorable = self._qc_datasource
+        # Reject unenforceable restrictions before provider identity or cache 
reads.
+        rls: list[str] = security_manager.get_rls_cache_key(datasource)

Review Comment:
   `SemanticView.get_extra_cache_keys` returns `[]`, so this hoist has no 
observable effect at this head; moving the call back below it passes all 1682 
tests in the touched suites. To lock the ordering, give `get_extra_cache_keys` 
an AssertionError side_effect in the cached-read test.



##########
docs/docs/using-superset/embedding.mdx:
##########
@@ -163,7 +163,7 @@ One caveat when the host page lives on a different site 
than Superset: the defau
 ## Security Notes
 
 - **Guest tokens expire** — their lifetime is controlled by the 
`GUEST_TOKEN_JWT_EXP_SECONDS` config (default: 5 minutes). Refresh tokens 
before they expire using a token refresh mechanism in your host app.
-- **Row-level security** — pass `rls` rules in the guest token request to 
restrict which rows are visible to the embedded user.
+- **Row-level security** — pass `rls` rules in the guest token request to 
restrict which rows are visible to the embedded user. Semantic views cannot 
enforce guest-token SQL clauses, so queries and cached-result reads are 
rejected when a global rule or a rule scoped to the semantic view applies. Read 
permissions do not override these restrictions. Semantic views remain 
accessible when no guest rule applies; SQL datasets continue to enforce their 
applicable rules.

Review Comment:
   Guest `rls` rules carry only a bare `dataset` integer, and SQL datasets and 
semantic views have separate ID spaces, so a rule meant for SQL dataset 7 also 
refuses semantic view 7. A single global rule also refuses every semantic view. 
Both fail closed, but worth stating here for hosts.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to