mikebridge commented on code in PR #44987:
URL: https://github.com/apache/superset/pull/44987#discussion_r4191545854
##########
docs/docs/using-superset/embedding.mdx:
##########
@@ -163,7 +163,7 @@ One caveat when the host page lives on a different site
than Superset: the defau
## Security Notes
- **Guest tokens expire** — their lifetime is controlled by the
`GUEST_TOKEN_JWT_EXP_SECONDS` config (default: 5 minutes). Refresh tokens
before they expire using a token refresh mechanism in your host app.
-- **Row-level security** — pass `rls` rules in the guest token request to
restrict which rows are visible to the embedded user.
+- **Row-level security** — pass `rls` rules in the guest token request to
restrict which rows are visible to the embedded user. Semantic views cannot
enforce guest-token SQL clauses, so queries and cached-result reads are
rejected when a global rule or a rule scoped to the semantic view applies. Read
permissions do not override these restrictions. Semantic views remain
accessible when no guest rule applies; SQL datasets continue to enforce their
applicable rules.
Review Comment:
Thanks for calling this out. Both cases deliberately fail closed; I've added
a short host-facing note in 7f61aa4576, and typed datasource matching is
handled in #45002.
##########
superset/common/query_context_processor.py:
##########
@@ -428,7 +428,9 @@ def query_cache_key(self, query_obj: QueryObject, **kwargs:
Any) -> str | None:
"""
Returns a QueryObject cache key for objects in self.queries
"""
- datasource = self._qc_datasource
+ datasource: Explorable = self._qc_datasource
+ # Reject unenforceable restrictions before provider identity or cache
reads.
+ rls: list[str] = security_manager.get_rls_cache_key(datasource)
Review Comment:
Thanks. In 7f61aa4576 the cached-read test makes extra-cache-key collection
raise if it is reached before the guest-RLS refusal. Moving the RLS check below
it fails all four restricted cases; with the current ordering all 25 tests in
the file pass.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]