luizotavio32 opened a new pull request, #42864: URL: https://github.com/apache/superset/pull/42864
`query_context_modified` compared a request's `metrics`, `columns`, `groupby` and `orderby` against identically-named keys in the chart's `params`. Charts save those values under whichever control names their viz type uses, so a guest merely loading an embedded dashboard was rejected as a tamperer: big number and pie store `metric`, bubble stores `x`/`y`/`size`, sankey stores `source`/`target`, time series stores `x_axis`. Each request key is now compared against every equivalent stored control, and `orderby` against any metric or column the chart already reads, since charts sort by their own metric on initial load without user interaction. Values are normalized before comparison so the same underlying column compares equal however it is spelled — adhoc references that only point back at a physical column collapse to its name, synthesized `BASE_AXIS` markers are shed, sort pairs reduce to the expression they sort on, and scalar-valued controls are no longer iterated character by character. Matching itself stays exact: only the shape of a value is normalized, never its identity, so a collapsed reference still has to match something stored on the chart. Pointing at an unrelated column or wrapping free-form SQL grants no extra access. The comparison helpers move to `superset/security/guest_payload.py`; `freeze_value` is re-exported from `superset.security.manager` for compatibility. <!--- Please write the PR title following the conventions at https://www.conventionalcommits.org/en/v1.0.0/ Example: fix(dashboard): load charts correctly --> ### SUMMARY <!--- Describe the change below, including rationale and design decisions --> ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF <!--- Skip this if not applicable --> ### TESTING INSTRUCTIONS <!--- Required! What steps can be taken to manually verify the changes? --> ### ADDITIONAL INFORMATION <!--- Check any relevant boxes with "x" --> <!--- HINT: Include "Fixes #nnn" if you are fixing an existing issue --> - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Migration is atomic, supports rollback & is backwards-compatible - [ ] Confirm DB migration upgrade and downgrade tested - [ ] Runtime estimates and downtime expectations provided - [ ] Introduces new feature or API - [ ] Removes existing feature or API -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
