rusackas commented on code in PR #44626:
URL: https://github.com/apache/superset/pull/44626#discussion_r4100035743


##########
superset/security/password_change.py:
##########
@@ -42,25 +44,31 @@
 # Flask endpoints take the form ``<ViewClass>.<method>`` (or a bare name for
 # function views). The following must remain reachable while a password change
 # is pending, otherwise the redirect would loop: the auth views (login/logout
-# for every auth backend), the password-reset and user-info-edit views, static
-# assets, and the health blueprint. We match the *view-class* component (the 
part
-# before the dot) exactly against the allow-list below rather than doing a
-# substring search, so unrelated endpoints that merely share a substring (e.g.
-# an "Author"-named view, or any name containing "health"/"static") are not
-# accidentally exempted from enforcement.
+# for every auth backend), the SPA profile page and the APIs its password
+# change modal needs (the current-user API it submits to and the CSRF token
+# endpoint), the legacy user-info-edit view, static assets, and the health
+# blueprint. We match the *view-class* component (the part before the dot)
+# exactly against the allow-list below rather than doing a substring search, so
+# unrelated endpoints that merely share a substring (e.g. an "Author"-named
+# view, or any name containing "health"/"static") are not accidentally exempted
+# from enforcement.
 _EXEMPT_VIEW_CLASSES = frozenset(
     {
         "AuthDBView",
         "AuthLDAPView",
         "AuthOAuthView",
         "AuthOIDView",
         "AuthRemoteUserView",
-        "ResetMyPasswordView",
-        "ResetPasswordView",
+        "CurrentUserRestApi",
+        "SecurityRestApi",

Review Comment:
   Good catch, narrowed it to the exact endpoints the profile page calls 
(`GET`/`PUT /api/v1/me/` and the CSRF token), so `guest_token` and the rest of 
that API stay behind the gate, with a test pinning that down.



##########
superset-frontend/src/features/userInfo/UserInfoModal.tsx:
##########
@@ -39,7 +39,7 @@ function UserInfoModal({
 
   const requiredFields = isEditMode
     ? ['first_name', 'last_name']
-    : ['password', 'confirm_password'];
+    : ['current_password', 'password', 'confirm_password'];

Review Comment:
   Good catch, `current_password` is optional in the modal now and only sent 
when filled in, while the API still requires and checks it whenever the account 
actually has a stored password.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to