mikebridge commented on code in PR #45060:
URL: https://github.com/apache/superset/pull/45060#discussion_r4231331328


##########
superset/common/query_context_factory.py:
##########
@@ -72,6 +75,27 @@ def create(  # pylint: disable=too-many-arguments
         result_type = result_type or ChartDataResultType.FULL
         result_format = result_format or ChartDataResultFormat.JSON
 
+        if (
+            self._authorize_semantic_before_metadata
+            and datasource_model_instance is not None
+            and DatasourceType(datasource["type"]) == 
DatasourceType.SEMANTIC_VIEW
+        ):
+            # Guest dashboard and payload checks need the completed query 
context,
+            # and an operator EXTRA_RAISE_FOR_ACCESS_BYPASS hook may read the
+            # request's queries; keep their authorization path and timing 
unchanged.
+            if not security_manager.is_guest_user() and not 
current_app.config.get(

Review Comment:
   Agreed, thanks. Fixed in 88df4e265a: the early check now runs only when the 
configured security manager keeps the stock `raise_for_access`. An override 
receives the complete query context through the existing final check, as with 
the `EXTRA_RAISE_FOR_ACCESS_BYPASS` carve-out.
   
   - The new regression test installs a manager that refuses a query context 
without queries. It returns 403 on the previous head and 200 with the guard.
   - The stock-manager tests still pin the early check: denied requests skip 
provider metadata, and an allowed request makes two query-context decisions.
   - Class-level lookup follows inherited methods and mixin resolution while 
preserving instance spies. The `CUSTOM_SECURITY_MANAGER` comment documents that 
overriding this method opts out of the early metadata check.
   
   Codex independently verified all 8 integration cases, 255 focused unit 
tests, and the branch pre-commit checks.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to