Antonio-RiveroMartnez commented on PR #44426:
URL: https://github.com/apache/superset/pull/44426#issuecomment-5774359914

   > I feel it's not a great solution from a security standpoint..
   
   Yes, I understand the drawbacks of supporting extra APIs in your app that 
you would never support or use and the security risk it might represent, 
however, I do believe we must find ways to not perpetuate this pattern of 
what's supposed to be runtime evaluated like a feature flag injected into boot 
sequence files.
   Not saying enabling the APIs is the best solution, probably the solution 
requires some changes in FAB etc, so yeah, even though I naively started the PR 
assuming it would have been an quick win, the way I see it, it's turning out to 
be something that requires more than just this PR.
   
   So, I'll close this for now, and we can use this thread or start a new one 
somewhere else to facilitate such broader discussion.
   
   Thanks both @villebro @rusackas 
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to