lukegranto23 opened a new pull request, #45089: URL: https://github.com/apache/superset/pull/45089
## Summary - Add `dblink`, `dblink_exec`, and `dblink_connect` to `DISALLOWED_SQL_FUNCTIONS["postgresql"]` in `config.py` - Add `DBLINK`, `DBLINK_EXEC`, and several `PG_*` state-mutating functions to `_MUTATING_FUNCTION_NAMES` in `superset/sql/parse.py` `dblink_exec` opens a separate database connection and auto-commits, so `SELECT dblink_exec(connstr, 'DELETE FROM table')` bypasses the `allow_dml=False` read-only gate — the outer statement is a SELECT, `has_mutation()` returns False, but the write persists via the autonomous connection. Related: SUPERSETSEC-136. The `pg_*` additions (`pg_cancel_backend`, `pg_reload_conf`, `pg_stat_reset`, `pg_switch_wal`, `pg_logical_emit_message`, `pg_create_restore_point`, `pg_drop_replication_slot`, `pg_rotate_logfile`) are PostgreSQL functions that mutate server state but parse as function calls inside a SELECT. ## Test plan - [ ] Verify `SELECT dblink_exec(...)` is now blocked on `allow_dml=False` connections - [ ] Verify `SELECT pg_cancel_backend(...)` is now blocked - [ ] Verify existing denylist entries still work - [ ] Verify non-PostgreSQL dialects are unaffected -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
