codeant-ai-for-open-source[bot] commented on code in PR #44453:
URL: https://github.com/apache/superset/pull/44453#discussion_r4055406514
##########
superset/db_engine_specs/bigquery.py:
##########
@@ -296,10 +341,32 @@ class BigQueryEngineSpec(BaseEngineSpec): # pylint:
disable=too-many-public-met
supports_dynamic_schema = True
supports_grouping_sets = True
+ # Per-user OAuth2 (SIP-85). When the database has "Impersonate logged in
user"
+ # enabled and an OAuth2 client is configured, each user authorizes Superset
+ # against their own Google account and every query runs with their BigQuery
+ # IAM permissions instead of the shared service account or ADC. Operators
+ # can widen the scope (e.g. drive.readonly for external tables backed by
+ # Google Sheets) in `DATABASE_OAUTH2_CLIENTS`.
+ supports_oauth2 = True
+ oauth2_scope = "https://www.googleapis.com/auth/bigquery"
+ oauth2_authorization_request_uri = ( # pylint: disable=invalid-name
+ "https://accounts.google.com/o/oauth2/v2/auth"
+ )
+ oauth2_token_request_uri = "https://oauth2.googleapis.com/token" # noqa:
S105
+ # Google only returns a refresh token for offline access with an explicit
+ # consent prompt.
+ oauth2_additional_auth_uri_query_params = {
+ "access_type": "offline",
+ "include_granted_scopes": "false",
+ "prompt": "consent",
+ }
+ oauth2_exception = (OAuth2RedirectError, *_OAUTH2_DRIVER_EXCEPTIONS)
Review Comment:
**Suggestion:** `RefreshError` and `Unauthorized` also occur with
service-account or ADC credentials, so shared-credential failures incorrectly
redirect users into OAuth authorization.
**Assessment:** ๐ `Major` ยท ๐ `Occurrence: Sometimes` ยท ๐ท๏ธ `Incorrect
condition logic`
[](https://docs.codeant.ai/cli/resolve-pr-comments-skill)
[](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=0170e89e45014aa9a64e6492a5f731a8&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
[](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=0170e89e45014aa9a64e6492a5f731a8&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
<details>
<summary><b>Prompt for AI Agent ๐ค </b></summary>
```mdx
This is a comment left during a code review.
**Path:** superset/db_engine_specs/bigquery.py
**Line:** 363:363
**Comment:**
*Incorrect Condition Logic: `RefreshError` and `Unauthorized` also
occur with service-account or ADC credentials, so shared-credential failures
incorrectly redirect users into OAuth authorization.
Validate the correctness of the flagged issue. If correct, How can I resolve
this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask
user if the user wants to fix the rest of the comments as well. if said yes,
then fetch all the comments validate the correctness and implement a minimal fix
```
</details>
<a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=d622bb72faed7a98e0fc592fd1e660f33ca12903be11cc17b1f9bfbf643855df&reaction=like'>๐</a>
| <a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=d622bb72faed7a98e0fc592fd1e660f33ca12903be11cc17b1f9bfbf643855df&reaction=dislike'>๐</a>
##########
superset/db_engine_specs/bigquery.py:
##########
@@ -706,12 +773,14 @@ def df_to_sql(
"project_id": engine.url.host,
}
- # Add credentials if they are set on the SQLAlchemy dialect.
-
+ # Add credentials if they are set on the SQLAlchemy dialect, or use the
+ # user's own OAuth2 token so uploads don't fall back to ADC.
if creds := engine.dialect.credentials_info:
to_gbq_kwargs["credentials"] = (
service_account.Credentials.from_service_account_info(creds)
)
+ elif user_token := cls._get_oauth2_user_token(database):
+ to_gbq_kwargs["credentials"] = OAuth2Credentials(token=user_token)
Review Comment:
**Suggestion:** Uploads skip the user token whenever dialect credentials
exist, causing OAuth-enabled connections retaining service-account fields to
upload as the shared account.
**Assessment:** ๐ `Major` ยท ๐ `Occurrence: Sometimes` ยท ๐ท๏ธ `Incorrect
condition logic`
[](https://docs.codeant.ai/cli/resolve-pr-comments-skill)
[](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=15eac81d719c47a094d61c17f052b992&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
[](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=15eac81d719c47a094d61c17f052b992&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
<details>
<summary><b>Prompt for AI Agent ๐ค </b></summary>
```mdx
This is a comment left during a code review.
**Path:** superset/db_engine_specs/bigquery.py
**Line:** 778:783
**Comment:**
*Incorrect Condition Logic: Uploads skip the user token whenever
dialect credentials exist, causing OAuth-enabled connections retaining
service-account fields to upload as the shared account.
Validate the correctness of the flagged issue. If correct, How can I resolve
this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask
user if the user wants to fix the rest of the comments as well. if said yes,
then fetch all the comments validate the correctness and implement a minimal fix
```
</details>
<a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=bb0385993efa3d17a642693c446dbbb2701b099b45568506009eccf1bb402fcb&reaction=like'>๐</a>
| <a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=bb0385993efa3d17a642693c446dbbb2701b099b45568506009eccf1bb402fcb&reaction=dislike'>๐</a>
##########
superset/db_engine_specs/bigquery.py:
##########
@@ -274,6 +306,19 @@ class BigQueryEngineSpec(BaseEngineSpec): # pylint:
disable=too-many-public-met
}
},
},
+ {
+ "name": "User OAuth2",
+ "description": (
+ "Each user authorizes Superset against their own Google "
+ "account and queries run with their BigQuery IAM
permissions. "
+ "Enable 'Impersonate logged in user' on the connection and
"
+ "register a Google OAuth client under "
+ "DATABASE_OAUTH2_CLIENTS['Google BigQuery'] in "
+ "superset_config.py, or as oauth2_client_info in Secure
Extra. "
+ "Use a plain bigquery://{project_id} URI without service "
Review Comment:
**Suggestion:** The documented OAuth-only setup uses no service credentials,
but URI construction still requires `credentials_info`, so this advertised
connection cannot be created.
**Assessment:** ๐ `Major` ยท ๐ `Occurrence: Sometimes` ยท ๐ท๏ธ `Api mismatch`
[](https://docs.codeant.ai/cli/resolve-pr-comments-skill)
[](https://app.codeant.ai/fix-in-ide?tool=cursor&prompt_id=bf32b11c6411409b952a439b6c28b30f&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
[](https://app.codeant.ai/fix-in-ide?tool=vscode-claude&prompt_id=bf32b11c6411409b952a439b6c28b30f&service=github&base_url=https%3A%2F%2Fgithub.com&org=apache&repo=apache%2Fsuperset)
<details>
<summary><b>Prompt for AI Agent ๐ค </b></summary>
```mdx
This is a comment left during a code review.
**Path:** superset/db_engine_specs/bigquery.py
**Line:** 317:318
**Comment:**
*Api Mismatch: The documented OAuth-only setup uses no service
credentials, but URI construction still requires `credentials_info`, so this
advertised connection cannot be created.
Validate the correctness of the flagged issue. If correct, How can I resolve
this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask
user if the user wants to fix the rest of the comments as well. if said yes,
then fetch all the comments validate the correctness and implement a minimal fix
```
</details>
<a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=e759e3d1da5ab707f843c9bc10b834cd72b773acf9b1cf220772bedc3e307528&reaction=like'>๐</a>
| <a
href='https://app.codeant.ai/feedback?pr_url=https%3A%2F%2Fgithub.com%2Fapache%2Fsuperset%2Fpull%2F44453&comment_hash=e759e3d1da5ab707f843c9bc10b834cd72b773acf9b1cf220772bedc3e307528&reaction=dislike'>๐</a>
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]