lukegranto23 opened a new pull request, #45089:
URL: https://github.com/apache/superset/pull/45089

   ## Summary
   
   - Add `dblink`, `dblink_exec`, and `dblink_connect` to 
`DISALLOWED_SQL_FUNCTIONS["postgresql"]` in `config.py`
   - Add `DBLINK`, `DBLINK_EXEC`, and several `PG_*` state-mutating functions 
to `_MUTATING_FUNCTION_NAMES` in `superset/sql/parse.py`
   
   `dblink_exec` opens a separate database connection and auto-commits, so 
`SELECT dblink_exec(connstr, 'DELETE FROM table')` bypasses the 
`allow_dml=False` read-only gate — the outer statement is a SELECT, 
`has_mutation()` returns False, but the write persists via the autonomous 
connection. Related: SUPERSETSEC-136.
   
   The `pg_*` additions (`pg_cancel_backend`, `pg_reload_conf`, 
`pg_stat_reset`, `pg_switch_wal`, `pg_logical_emit_message`, 
`pg_create_restore_point`, `pg_drop_replication_slot`, `pg_rotate_logfile`) are 
PostgreSQL functions that mutate server state but parse as function calls 
inside a SELECT.
   
   ## Test plan
   
   - [ ] Verify `SELECT dblink_exec(...)` is now blocked on `allow_dml=False` 
connections
   - [ ] Verify `SELECT pg_cancel_backend(...)` is now blocked
   - [ ] Verify existing denylist entries still work
   - [ ] Verify non-PostgreSQL dialects are unaffected


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to