mikebridge opened a new pull request, #45071:
URL: https://github.com/apache/superset/pull/45071

   ### SUMMARY
   
   Reject hard deletion of semantic views or layers while live charts, live 
dashboards containing those charts or targeting the views in native filters or 
display controls, or active reports/alerts depend on them. Return 409 with 
`total`, up to 20 dependents visible through corresponding list-access filters, 
and `inaccessible_count` for the rest. Each dependent's `id` is the integer key 
that the existing chart, dashboard and report REST endpoints accept, so a 
client can act on it directly. Schedule types are lowercase.
   
   The dashboard target check uses a SQL `LIKE` prefilter followed by exact 
Python parsing of typed `(datasourceType, datasetId)` targets in both dashboard 
control lists; legacy id-only targets remain SQL datasets. Malformed dashboard 
metadata is ignored with debug logging of the dashboard ID only.
   
   Limitations:
   - The guard is best-effort: a dependent created or re-pointed between the 
check and the delete can still be orphaned. No chart/dashboard-write locking is 
added.
   - Deliberately raw, unicode-escaped `datasourceType` text can evade the 
`LIKE` prefilter; normal dashboard writers serialize the literal ASCII value.
   - The active `report_schedule` reference lookup is intentionally unindexed, 
since it only runs on a protected delete; an index can follow if volumes 
warrant.
   - The dashboard candidate scan is bounded by workspace data, not a hard cap; 
the candidate query requests 1,000-row streaming batches where the database 
driver supports them.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   Not applicable; API behavior only.
   
   ### TESTING INSTRUCTIONS
   
   Create a semantic view with a live chart, a dashboard containing it, a 
native-filter-only dashboard targeting it, a display-control-only dashboard 
targeting it, and active alert/report schedules. Verify single-view, bulk-view 
and layer deletes return 409 with lowercase types. Give a source editor no 
dashboard read access and verify the response counts but does not name it. 
Verify same-ID table/legacy targets, malformed metadata, archived 
dashboards/charts and inactive schedules do not block deletion; a string 
semantic-view ID does. Run the focused command and API tests and the 
semantic-layer coverage gate.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [x] Required feature flags: `SEMANTIC_LAYERS`
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [x] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to