sadpandajoe commented on code in PR #45060:
URL: https://github.com/apache/superset/pull/45060#discussion_r4235847181
##########
superset/common/query_context_factory.py:
##########
@@ -27,23 +27,40 @@
from superset.daos.chart import ChartDAO
from superset.daos.datasource import DatasourceDAO
from superset.explorables.base import Explorable
+from superset.extensions import security_manager
from superset.models.slice import Slice
+from superset.security.manager import SupersetSecurityManager
from superset.superset_typing import Column
from superset.utils.core import DatasourceDict, DatasourceType, is_adhoc_column
if TYPE_CHECKING:
from superset.connectors.sqla.models import BaseDatasource
+def _uses_stock_raise_for_access() -> bool:
+ """Whether the security manager keeps the stock ``raise_for_access``.
+
+ The semantic preflight passes an empty ``queries`` list, which only the
+ stock check is known not to read. ``__class__`` resolves through the
+ security manager proxy to the configured manager's class.
+ """
+ return (
+ security_manager.__class__.raise_for_access
Review Comment:
This detects an override by comparing the class attribute, so a security
manager that inherits the stock method but wraps it on the instance
(`self.raise_for_access = ...` in `__init__`), or a `superset_config.py` that
reassigns `SupersetSecurityManager.raise_for_access` to a wrapper, still counts
as stock. The wrapper then runs in the preflight with `queries=[]`, and one
that reads `query_context.queries[0]` for metric or column checks raises
`IndexError` (500) on a semantic-view request that returned 200 before this
change. Could this compare the resolved bound method on the proxied manager (or
the instance `__dict__`) instead, so those cases skip the preflight like a
subclass override does?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]