luizotavio32 opened a new pull request, #42864:
URL: https://github.com/apache/superset/pull/42864

   `query_context_modified` compared a request's `metrics`, `columns`, 
`groupby` and `orderby` against identically-named keys in the chart's `params`. 
Charts save those values under whichever control names their viz type uses, so 
a guest merely loading an embedded dashboard was rejected as a tamperer: big 
number and pie store `metric`, bubble stores `x`/`y`/`size`, sankey stores 
`source`/`target`, time series stores `x_axis`.
   
   Each request key is now compared against every equivalent stored control, 
and `orderby` against any metric or column the chart already reads, since 
charts sort by their own metric on initial load without user interaction. 
Values are normalized before comparison so the same underlying column compares 
equal however it is spelled — adhoc references that only point back at a 
physical column collapse to its name, synthesized `BASE_AXIS` markers are shed, 
sort pairs reduce to the expression they sort on, and scalar-valued controls 
are no longer iterated character by character.
   
   Matching itself stays exact: only the shape of a value is normalized, never 
its identity, so a collapsed reference still has to match something stored on 
the chart. Pointing at an unrelated column or wrapping free-form SQL grants no 
extra access.
   
   The comparison helpers move to `superset/security/guest_payload.py`; 
`freeze_value` is re-exported from `superset.security.manager` for 
compatibility.
   
   <!---
   Please write the PR title following the conventions at 
https://www.conventionalcommits.org/en/v1.0.0/
   Example:
   fix(dashboard): load charts correctly
   -->
   
   ### SUMMARY
   <!--- Describe the change below, including rationale and design decisions -->
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   <!--- Skip this if not applicable -->
   
   ### TESTING INSTRUCTIONS
   <!--- Required! What steps can be taken to manually verify the changes? -->
   
   ### ADDITIONAL INFORMATION
   <!--- Check any relevant boxes with "x" -->
   <!--- HINT: Include "Fixes #nnn" if you are fixing an existing issue -->
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to