Antonio-RiveroMartnez commented on PR #44426: URL: https://github.com/apache/superset/pull/44426#issuecomment-5774359914
> I feel it's not a great solution from a security standpoint.. Yes, I understand the drawbacks of supporting extra APIs in your app that you would never support or use and the security risk it might represent, however, I do believe we must find ways to not perpetuate this pattern of what's supposed to be runtime evaluated like a feature flag injected into boot sequence files. Not saying enabling the APIs is the best solution, probably the solution requires some changes in FAB etc, so yeah, even though I naively started the PR assuming it would have been an quick win, the way I see it, it's turning out to be something that requires more than just this PR. So, I'll close this for now, and we can use this thread or start a new one somewhere else to facilitate such broader discussion. Thanks both @villebro @rusackas -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
