gabotorresruiz commented on code in PR #43805:
URL: https://github.com/apache/superset/pull/43805#discussion_r3929017822


##########
superset/tasks/export_dashboard_excel.py:
##########
@@ -98,6 +117,25 @@ def export_lock_params(user_id: int, dashboard_id: int) -> 
dict[str, int]:
     return {"user_id": user_id, "dashboard_id": dashboard_id}
 
 
+def guest_lock_slot(guest_token: GuestToken | None) -> int:
+    """A stable per-guest lock slot derived from the token's identity, so
+    concurrent guests on the same dashboard throttle independently instead of
+    all sharing slot 0 (where the second guest's export is refused with no
+    job id and no email fallback). Anonymous requesters (no token) share 0.
+    """
+    if not guest_token:
+        return 0
+    user = guest_token.get("user") or {}
+    resources = guest_token.get("resources") or []
+    fingerprint = json.dumps(

Review Comment:
   Good catch, fixed in 8bf3549: guest_lock_slot now folds rls_rules into the 
fingerprint alongside username and resources, so embedded guests sharing a 
dashboard with a shared or absent username are distinguished by their RLS 
claims and no longer collide on one slot. It is computed identically at acquire 
and release, and covered by a unit test asserting that the same username and 
resources with different RLS gets a distinct slot.



##########
docs/docs/using-superset/exporting-dashboard-data.mdx:
##########
@@ -72,33 +91,46 @@ will not register.
 
 ## Configuration keys
 
-| Key                             | Default                | Description       
                                                                                
                                                                                
|
-| ------------------------------- | ---------------------- | 
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
 |
-| `EXCEL_EXPORT_S3_BUCKET`        | `None`                 | Destination 
bucket. Required; `501` if unset.                                               
                                                                                
      |
-| `EXCEL_EXPORT_S3_KEY_PREFIX`    | `"dashboard-exports/"` | Key prefix: 
`{prefix}{dashboard_id}/{job_id}.xlsx`.                                         
                                                                                
      |
-| `EXCEL_EXPORT_LINK_TTL_SECONDS` | `86400`                | Lifetime of the 
pre-signed download URL (24h).                                                  
                                                                                
  |
-| `EXCEL_EXPORT_S3_CLIENT_KWARGS` | `{}`                   | Extra kwargs for 
`boto3.client("s3", ...)` — e.g. `region_name`, or `endpoint_url` for 
MinIO/LocalStack.                                                               
           |
-| `EXCEL_EXPORT_TABLE_VIZ_TYPES`  | `None`                 | Viz types kept 
tabular in **Export Images to Excel** mode; every other type is embedded as an 
image. `None` uses the built-in default (`table`, `pivot_table`, 
`pivot_table_v2`). |
-| `EXCEL_EXPORT_QUERY_CONTEXT_BUILDER` | `None`            | Optional 
`Callable[[form_data_dict], dict \| None]` to build a query context for a chart 
missing a saved one, tried before the built-in form-data rebuild. Point it at a 
service that runs the chart's real frontend `buildQuery` to faithfully export 
viz types the built-in rebuild can't handle. Must return `None` when it can't 
build faithfully, so the export falls back. |
-
-Credentials and region resolve through the standard boto3 chain (environment
-variables, shared config, or instance role) unless overridden via
-`EXCEL_EXPORT_S3_CLIENT_KWARGS`. The worker needs `s3:PutObject` on the bucket.
+| Key                                    | Default                | 
Description                                                                     
                                                                                
                  |
+| -------------------------------------- | ---------------------- | 
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
 |
+| `EXPORT_STORAGE["bucket"]`             | unset                  | 
Destination bucket. Required; `501` if unset.                                   
                                                                                
                  |
+| `EXPORT_STORAGE["backend"]`            | unset                  | Storage 
backend instance: `S3ExportStorage()` (`superset.utils.s3`), 
`GCSExportStorage()` (`superset.utils.gcs`), or a custom 
`superset.utils.export_storage.ExportStorage` implementation. Required; `501` 
if unset. |
+| `EXPORT_STORAGE["key_prefix"]`         | `"dashboard-exports/"` | Object 
key/blob prefix: `{prefix}{dashboard_id}/{job_id}.xlsx`. A callable (`() -> 
str`) is invoked per export, for prefixes only known in request/task context 
(e.g. per-tenant scoping of a shared bucket). |
+| `EXCEL_EXPORT_LINK_TTL_SECONDS`        | `86400`                | Lifetime 
of the Superset download link (24h) shared in the email and polling response. 
Each click streams the file from storage through Superset. |

Review Comment:
   Done in b689735: the EXCEL_EXPORT_LINK_TTL_SECONDS row now documents that 
guest token exports cap the link at one hour regardless of the configured 
value, since a guest retrieves the file within the polling window and has no 
email link to revisit later.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to