mikebridge opened a new pull request, #45060: URL: https://github.com/apache/superset/pull/45060
### SUMMARY For chart-data requests on a semantic view, the query context is built (which asks the semantic-layer provider for dimension and metric metadata) before the access check runs. A caller without access therefore still triggers provider calls before receiving a 403. This change avoids those unnecessary calls. - For ordinary (non-guest) chart-data requests on a semantic view, a metadata-free access check now runs before the query context is built. A caller without access gets the same 403 without the provider being called. - The full access check still runs before execution, exactly as before, so an early allow never widens access. - Embedded-guest requests are unchanged in this PR. Their access is derived from the dashboard and is handled separately. - SQL datasets are unaffected. - The error response is unchanged. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A (server-side change; the response is identical). Before, a denied ordinary request called the provider's metadata methods and then returned 403. After, it returns the same 403 with no provider metadata calls. ### TESTING INSTRUCTIONS Run `pytest tests/integration_tests/charts/semantic_metadata_authz_tests.py -q` (5 tests) and changed-file `pre-commit run`. The two denial tests (a direct denied request and a denied dashboard native-filter request) were written first and fail on the old code because the provider's metadata call happens before the 403; they pass now with zero provider dimension or metric calls. The remaining tests guard that an allowed caller still succeeds, that an embedded guest with dashboard access still succeeds, and that SQL dataset chart-data requests are unaffected. ### ADDITIONAL INFORMATION - [ ] Has associated issue - [ ] Required feature flags - [ ] Changes UI - [ ] Includes DB Migration - [ ] Introduces new feature or API - [ ] Removes existing feature or API Known follow-ups: - Document the invariant the early check relies on, that `raise_for_access` does not read `queries` for non-guest callers, and add a unit test so any drift breaks a test. - Allowed semantic requests now evaluate the access lookups twice (once in the early check, once in the full check). Both are read-only. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
