michael-s-molina commented on code in PR #24630:
URL: https://github.com/apache/superset/pull/24630#discussion_r1258748240


##########
superset-frontend/src/explore/components/SaveModal.tsx:
##########
@@ -125,7 +125,9 @@ class SaveModal extends React.Component<SaveModalProps, 
SaveModalState> {
     if (dashboardId) {
       try {
         const result = await this.loadDashboard(dashboardId);
-        if (result) {
+        if (
+          result?.owners.some((owner: any) => owner.id === this.props.userId)

Review Comment:
   Just to explain a little bit more. My concern is that security checks should 
always happen at the server side because it's really simple to edit the 
frontend scripts and bypass this types of checks.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to