codeant-ai-for-open-source[bot] commented on code in PR #41133: URL: https://github.com/apache/superset/pull/41133#discussion_r3571768629
########## superset/tasks/export_dashboard_excel.py: ########## @@ -0,0 +1,345 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +""" +Celery task that exports every chart on a dashboard to a single multi-sheet +``.xlsx`` file, uploads it to S3, and emails the requesting user a pre-signed +download link. + +In ``"data"`` mode the task re-runs each chart's saved query context under the +requesting user, applies the live dashboard filter state, and streams the results +row-by-row into a constant-memory workbook so large dashboards never load all +data at once. In ``"images"`` mode non-table charts are instead rendered to +images (through the same headless path as scheduled reports, reflecting the live +filters) and embedded, while table-like charts stay tabular. +""" + +from __future__ import annotations + +import logging +import os +import tempfile +from datetime import datetime, timedelta, timezone +from typing import Any + +from celery.exceptions import SoftTimeLimitExceeded +from flask import current_app, g + +from superset import db, security_manager +from superset.charts.data.dashboard_filter_context import ( + apply_dashboard_filter_context, + get_dashboard_filter_context, +) +from superset.charts.schemas import ChartDataQueryContextSchema +from superset.commands.chart.data.get_data_command import ChartDataCommand +from superset.common.chart_data import ChartDataResultFormat, ChartDataResultType +from superset.dashboards.excel_export import email +from superset.dashboards.excel_export.layout import get_charts_in_layout_order +from superset.dashboards.excel_export.screenshot import render_chart_image +from superset.extensions import cache_manager, celery_app +from superset.utils import json, s3 +from superset.utils.core import override_user +from superset.utils.excel_streaming import StreamingXlsxWriter + +logger = logging.getLogger(__name__) + +# Export modes: "data" streams every chart's tabular result (the default, +# unchanged behavior); "images" embeds non-table charts as rendered images and +# keeps only table-like charts tabular. +EXPORT_MODE_DATA = "data" +EXPORT_MODE_IMAGES = "images" + +# Viz types kept as tabular data in image mode; everything else is rendered as an +# image. Operators can override the set via ``EXCEL_EXPORT_TABLE_VIZ_TYPES``. +TABLE_VIZ_TYPES = {"table", "pivot_table_v2", "pivot_table"} + +EXPORT_SOFT_TIME_LIMIT = 600 +EXPORT_HARD_TIME_LIMIT = 660 +# TTL for the per-user+dashboard in-flight lock set by the API before enqueue. +# It outlives the hard time limit so a worker killed at that limit (which skips +# the ``finally`` cleanup) cannot hold the lock forever; the delete in +# ``finally`` is the fast path that frees it as soon as the task settles. +EXPORT_INFLIGHT_CACHE_TTL = EXPORT_HARD_TIME_LIMIT + 60 + + +class _ChartSkippedError(Exception): + """Signals a chart that could not be exported and should be listed as skipped.""" + + +def _chart_label(chart: Any) -> str: + """Human-readable label for a chart in the skipped-charts list.""" + return f"{chart.id} - {chart.slice_name or ''}".strip() + + +def _record_to_row(record: dict[str, Any], colnames: list[str]) -> list[Any]: + return [record.get(col) for col in colnames] + + +def _table_viz_types() -> set[str]: + """Viz types kept tabular in image mode (config override or built-in default).""" + return current_app.config.get("EXCEL_EXPORT_TABLE_VIZ_TYPES") or TABLE_VIZ_TYPES + + +def _renders_as_image(chart: Any, mode: str) -> bool: + """Whether this chart is embedded as an image rather than streamed as data.""" + return mode == EXPORT_MODE_IMAGES and chart.viz_type not in _table_viz_types() + + +def _write_chart_image_sheet( + writer: StreamingXlsxWriter, + chart: Any, + dashboard_id: int, + active_data_mask: dict[str, Any], + user: Any, +) -> None: + """ + Render a single chart to an image and embed it as its own sheet. + + :raises _ChartSkippedError: if the chart could not be rendered + """ + image = render_chart_image(chart, dashboard_id, active_data_mask, user) + if image is None: + raise _ChartSkippedError + writer.add_image_sheet(_chart_label(chart), image) + + +def _write_chart_sheets( + writer: StreamingXlsxWriter, + chart: Any, + dashboard_id: int, + active_data_mask: dict[str, Any], +) -> None: + """ + Run a single chart's query and stream its result(s) into the workbook. + + Charts may yield more than one query (e.g. mixed-series charts); each becomes + its own sheet. Raises if the chart cannot be exported, so the caller can skip + it and note it in the email. + """ + json_body = json.loads(chart.query_context) + # Override any stale saved values: we always want full JSON results. + json_body["result_format"] = ChartDataResultFormat.JSON + json_body["result_type"] = ChartDataResultType.FULL + json_body.pop("force", None) + + filter_context = get_dashboard_filter_context( + dashboard_id=dashboard_id, + chart_id=chart.id, + active_data_mask=active_data_mask, + ) + if filter_context.extra_form_data: + apply_dashboard_filter_context(json_body, filter_context.extra_form_data) + + # Jinja macros resolve form data from g.form_data; expose the saved context. + g.form_data = json_body + + query_context = ChartDataQueryContextSchema().load(json_body) + command = ChartDataCommand(query_context) + command.validate() + result = command.run() + + for index, query in enumerate(result["queries"]): + colnames = query.get("colnames") or [] + data = query.get("data") or [] + if index == 0: + name = f"{chart.id} - {chart.slice_name or ''}" + else: + name = f"{chart.id}.{index} - {chart.slice_name or ''}" + writer.add_sheet( + name, + colnames, + (_record_to_row(record, colnames) for record in data), + ) + + +def _build_workbook( + path: str, + dashboard: Any, + active_data_mask: dict[str, Any], + job_id: str, + mode: str, + user: Any, +) -> dict[str, list[str]]: + """Build the workbook on disk. + + Return the charts that could not be exported, grouped by the reason they + were omitted (see the ``email.ERROR_*`` reason keys), so the notification + can explain each group separately. + """ + errored: dict[str, list[str]] = {} + writer = StreamingXlsxWriter(path) + try: + for chart in get_charts_in_layout_order(dashboard): + label = _chart_label(chart) + as_image = _renders_as_image(chart, mode) + # Image charts render from their saved params and don't need a query + # context; data (and table) charts still do. + if not as_image and not chart.query_context: + errored.setdefault(email.ERROR_NO_QUERY_CONTEXT, []).append(label) + continue + try: + if as_image: + _write_chart_image_sheet( + writer, chart, dashboard.id, active_data_mask, user + ) + else: + _write_chart_sheets(writer, chart, dashboard.id, active_data_mask) + except SoftTimeLimitExceeded: + logger.warning( + "Chart %s timed out in dashboard export %s", chart.id, job_id + ) + errored.setdefault(email.ERROR_TIMEOUT, []).append(label) + except _ChartSkippedError: + logger.warning( + "Skipping chart %s in dashboard export %s (could not render)", + chart.id, + job_id, + ) + errored.setdefault(email.ERROR_GENERAL, []).append(label) + except Exception: # pylint: disable=broad-except + logger.exception( + "Skipping chart %s in dashboard export %s", chart.id, job_id + ) + errored.setdefault(email.ERROR_GENERAL, []).append(label) + + if writer.sheet_count == 0: + flat = [label for labels in errored.values() for label in labels] + writer.add_summary_sheet( + "Export Summary", + ["No chart data could be exported.", *flat], + ) + finally: + writer.close() + return errored + + +def _send_failure_email( + user: Any, dashboard_title: str, requested_at: datetime +) -> None: + if not (user and getattr(user, "email", None)): + return + try: + email.send_export_email( + user.email, + email.build_subject(dashboard_title, success=False), + email.build_failure_email(dashboard_title, requested_at), + ) + except Exception: # pylint: disable=broad-except + logger.exception("Failed to send export failure email") + + +@celery_app.task( + name="export_dashboard_excel", + bind=True, + soft_time_limit=EXPORT_SOFT_TIME_LIMIT, + time_limit=EXPORT_HARD_TIME_LIMIT, + max_retries=0, +) +def export_dashboard_excel( + self: Any, # pylint: disable=unused-argument + dashboard_id: int, + user_id: int, + active_data_mask: dict[str, Any], + job_id: str, + mode: str = EXPORT_MODE_DATA, + inflight_key: str | None = None, +) -> None: + """ + Export a dashboard's charts to an ``.xlsx`` and email a download link. + + :param dashboard_id: The dashboard to export + :param user_id: The requesting user (the task runs with their permissions) + :param active_data_mask: Live dashboard filter state keyed by native filter id + :param job_id: Correlation id, also the Celery task id and S3 object name + :param mode: ``"data"`` streams every chart's tabular result; ``"images"`` + embeds non-table charts as rendered images and keeps tables tabular + :param inflight_key: Cache key of the per-user+dashboard throttle lock, freed + when the task settles (the lock's TTL is the backstop) + """ + # pylint: disable=import-outside-toplevel + from superset.models.dashboard import Dashboard + + requested_at = datetime.now(tz=timezone.utc) + user = security_manager.get_user_by_id(user_id) + dashboard_title = "" + tmp_path: str | None = None + + try: + with override_user(user, force=False): + dashboard = ( + db.session.query(Dashboard).filter_by(id=dashboard_id).one_or_none() + ) + if dashboard is None: + raise ValueError(f"Dashboard {dashboard_id} not found") Review Comment: **Suggestion:** The task loads the dashboard but never re-checks dashboard authorization under the worker user. Because this runs asynchronously, permissions can change between enqueue and execution, and the task can still export data for a dashboard the user no longer has access to. Re-validate dashboard access in the task right after loading the dashboard and fail early on denied access. [security] <details> <summary><b>Severity Level:</b> Critical 🚨</summary> ```mdx ❌ Dashboard Excel export succeeds after dashboard access revocation. ⚠️ Asynchronous export_xlsx ignores updated dashboard authorization state. ``` </details> <details> <summary><b>Steps of Reproduction ✅ </b></summary> ```mdx 1. A user with dashboard export permission calls `POST /api/v1/dashboard/<pk>/export_xlsx/` (implemented in `DashboardRestApi.export_xlsx` at `superset/dashboards/api.py:1588-1689`). This endpoint verifies access via `security_manager.raise_for_access(dashboard=dashboard)` (`api.py:1654-1656`), constructs an in-flight lock key, and enqueues the Celery task `export_dashboard_excel` with `dashboard_id`, `user_id`, and `job_id` (`api.py:1676-1688`). 2. After enqueue but before the worker executes the task, an administrator revokes the user’s ability to access the dashboard (for example, by removing them from the dashboard’s viewers/editors so that subsequent `raise_for_access(dashboard=dashboard)` calls would fail). 3. When the Celery worker processes `export_dashboard_excel` (`superset/tasks/export_dashboard_excel.py:251-259`), it impersonates the user with `override_user(user, force=False)` (`export_dashboard_excel.py:281`) and then loads the `Dashboard` row using `db.session.query(Dashboard).filter_by(id=dashboard_id).one_or_none()` (`export_dashboard_excel.py:282-284`). There is no call to `security_manager.raise_for_access` or any other dashboard-level authorization check after loading the dashboard. 4. The task proceeds to build and upload the workbook by calling `_build_workbook` (`export_dashboard_excel.py:294-296`) and then streaming each chart’s data via `ChartDataCommand.run()` (`export_dashboard_excel.py:149-152`), uploading to S3 (`export_dashboard_excel.py:305-306`), and sending a success email with the download link (`export_dashboard_excel.py:309-322`). Because access is never revalidated under the current RBAC state, the user can receive a fresh export for a dashboard they no longer have permission to access. ``` </details> [](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=0a650d37f1754286a09ecf7482178fde&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset) [](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=0a650d37f1754286a09ecf7482178fde&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset) *(Use Cmd/Ctrl + Click for best experience)* <details> <summary><b>Prompt for AI Agent 🤖 </b></summary> ```mdx This is a comment left during a code review. **Path:** superset/tasks/export_dashboard_excel.py **Line:** 282:286 **Comment:** *Security: The task loads the dashboard but never re-checks dashboard authorization under the worker user. Because this runs asynchronously, permissions can change between enqueue and execution, and the task can still export data for a dashboard the user no longer has access to. Re-validate dashboard access in the task right after loading the dashboard and fail early on denied access. Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise. Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix ``` </details> <a href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F41133&comment_hash=051b1d0ad14ad457fd9dcf442d29a9a34c30fc56a4d69c5b8253728116cb9dad&reaction=like'>👍</a> | <a href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F41133&comment_hash=051b1d0ad14ad457fd9dcf442d29a9a34c30fc56a4d69c5b8253728116cb9dad&reaction=dislike'>👎</a> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
