codeant-ai-for-open-source[bot] commented on code in PR #45089:
URL: https://github.com/apache/superset/pull/45089#discussion_r4219795777


##########
superset/config.py:
##########
@@ -2481,6 +2481,20 @@ def engine_context_manager(  # pylint: 
disable=unused-argument
         # Other potentially dangerous functions
         "pg_sleep",
         "pg_terminate_backend",
+        # dblink functions can open separate connections and auto-commit
+        # writes, bypassing the read-only gate entirely
+        "dblink",
+        "dblink_exec",
+        "dblink_connect",

Review Comment:
   Yes. Add both `dblink_connect_u` and `dblink_send_query` to PostgreSQL’s 
`DISALLOWED_SQL_FUNCTIONS`: the former opens a connection, and the latter can 
dispatch remote DML asynchronously.
   
   For defense in depth, add them to `_MUTATING_FUNCTION_NAMES` as well. 
`dblink_send_query` clearly submits a potentially mutating query; 
`dblink_connect_u` changes connection state. I’d also add the existing 
`dblink_connect` entry to that set for consistency. `dblink_get_result` doesn’t 
prevent the risk—the remote query may already have run when `dblink_send_query` 
returns.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to