mikebridge opened a new pull request, #45062:
URL: https://github.com/apache/superset/pull/45062

   ### SUMMARY
   
   Follow-up to #44094, which made the certification tool refuse externally 
managed dashboards. The other MCP tools that change an existing dashboard did 
not apply the same rule, so an MCP client could edit a dashboard whose source 
of truth lives outside Superset.
   
   All MCP tools that change an existing dashboard now refuse a dashboard that 
is managed externally, using the same error shape as the certification refusal 
(`managed_externally=True`, with guidance not to retry). The refusal is 
returned after the editor-permission check and before any write, so a caller 
who cannot edit the dashboard does not learn whether it is managed.
   
   - Covered tools: owners, roles, certification, markdown/layout components, 
`update_dashboard`, add chart, remove chart, native filters, delete and restore.
   - A single shared guard (`managed_dashboard_refusal`) owns the check and the 
wording; certification and markdown now use it too. Six response schemas gain 
the `managed_externally` field.
   - Read-only tools are unchanged, as are dashboard creation and duplication, 
which produce a new dashboard rather than changing the source.
   - MCP is intentionally stricter than REST here: the REST update command 
still allows a local-only `published` change on a managed dashboard, while MCP 
refuses every mutation. This is noted in `UPDATING.md` and the MCP server docs.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A (MCP response behavior only). Before, for example, 
`manage_dashboard_owners` or `update_dashboard` on an externally managed 
dashboard changed it. After, they return a structured refusal with 
`managed_externally=True` and make no write.
   
   ### TESTING INSTRUCTIONS
   
   Run `pytest tests/unit_tests/mcp_service/dashboard -q` along with 
`tests/unit_tests/mcp_service/test_tool_description_constraints.py` and 
`tests/unit_tests/mcp_service/test_tool_inventory.py`.
   
   The managed-dashboard regression covers each of the ten mutation tools 
(written first; eight failed on the old code, the other two were the existing 
certification and markdown gates), a parametrized unmanaged case that confirms 
each tool still reaches its normal write path, and a case confirming that a 
non-editor gets the ordinary authorization response. Manually, call any of the 
mutation tools against an editable externally managed dashboard and confirm a 
`managed_externally=True` refusal and an unchanged dashboard, then repeat 
against an unmanaged dashboard and confirm the normal result.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue
   - [ ] Required feature flags
   - [ ] Changes UI
   - [ ] Includes DB Migration
   - [x] Introduces new feature or API: adds `managed_externally` to six MCP 
response schemas
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to