jfrag1 commented on code in PR #24630:
URL: https://github.com/apache/superset/pull/24630#discussion_r1258819699


##########
superset-frontend/src/explore/components/SaveModal.tsx:
##########
@@ -125,7 +125,9 @@ class SaveModal extends React.Component<SaveModalProps, 
SaveModalState> {
     if (dashboardId) {
       try {
         const result = await this.loadDashboard(dashboardId);
-        if (result) {
+        if (
+          result?.owners.some((owner: any) => owner.id === this.props.userId)

Review Comment:
   True, but only if you already have access to view that dashboard/its 
metadata anyways.  Nothing is being leaked that the user can't access normally; 
the `GET api/v1/dashboard/<pk>` endpoint has its own security and will 404 if 
the user shouldn't have access to view it



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to