aminghadersohi opened a new pull request, #44603:
URL: https://github.com/apache/superset/pull/44603

   ### SUMMARY
   Fixes [SC-121713](https://app.shortcut.com/preset/story/121713).
   
   Verified against fetched `apache/superset` master 
`8141d666d6decade7de8406a0cc40c705289517d`:
   - `ChartErrorBuilder.column_not_found_error` interpolated its `Check 
available columns` fallback into `Did you mean: …?`.
   - `DatasetValidator._build_column_error` accepted dataset context but did 
not attach it to the error.
   - Fuzzy matching included saved metrics even for physical-column references.
   
   Return actual physical-column candidates (up to three), or explicit no-match 
guidance. Attach up to ten escaped, length-limited column names from the 
authorized dataset; omit metric expressions and other column metadata. Check 
dataset access before constructing context. Multiple-column suggestions no 
longer echo caller-supplied invalid references. Existing structured error 
types, sanitization, and suggestion limits remain intact.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   Not applicable (MCP response).
   
   Before: `Did you mean: Check available columns?`, with null dataset context.
   After: explicit no-match guidance plus `month`, `category`, and `revenue` in 
bounded context. Near match `revnue` suggests `revenue`; denied dataset access 
returns no metadata.
   
   ### TESTING INSTRUCTIONS
   Reproduced the exact reported `save_chart=false` bar request against an 
authorized mocked dataset 268 containing `month`, `category`, and `revenue`, 
through the real `generate_chart` validation pipeline. The regression test 
failed on the original placeholder before the fix.
   
   ```bash
   PYTHONPATH=.:superset-core/src python -m pytest \
     tests/unit_tests/mcp_service/chart/validation \
     tests/unit_tests/mcp_service/chart/test_compile.py \
     tests/unit_tests/mcp_service/chart/tool/test_column_suggestions.py \
     tests/unit_tests/mcp_service/chart/tool/test_generate_chart.py \
     tests/unit_tests/mcp_service/utils/test_error_sanitization.py \
     tests/unit_tests/mcp_service/utils/test_sanitization.py \
     -q --disable-warnings
   ```
   **333 passed**, using `/home/agorpg/tmp/superset-mcp-tests/bin/python`.
   
   `pre-commit run` on the five explicitly staged changed files: **passed**, 
including mypy, Ruff, and pylint.
   
   Coverage includes near-match, no-match, empty schema, denied dataset access, 
saved-metric exclusion, multiple invalid columns, escaping, response bounds, 
and no raw invalid references in suggestions. Two compile-test expectations 
were updated from saved-metric suggestions to column-only guidance and schema 
context; no security checks were weakened.
   
   For manual verification, repeat the story request on a dataset you may 
access, then try `revnue` and a denied dataset ID. Verify the error remains 
structured and the denied response contains no dataset metadata.
   
   UNVERIFIED: deployed staging/production versions and live staging behavior. 
No dev environment was started, and no production data was changed.
   
   ### ADDITIONAL INFORMATION
   - [x] Has associated issue: 
[SC-121713](https://app.shortcut.com/preset/story/121713)
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   AI-assisted implementation; kept in draft for human review.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to