codeant-ai-for-open-source[bot] commented on code in PR #44626:
URL: https://github.com/apache/superset/pull/44626#discussion_r4100034980
##########
superset/security/password_change.py:
##########
@@ -42,25 +44,31 @@
# Flask endpoints take the form ``<ViewClass>.<method>`` (or a bare name for
# function views). The following must remain reachable while a password change
# is pending, otherwise the redirect would loop: the auth views (login/logout
-# for every auth backend), the password-reset and user-info-edit views, static
-# assets, and the health blueprint. We match the *view-class* component (the
part
-# before the dot) exactly against the allow-list below rather than doing a
-# substring search, so unrelated endpoints that merely share a substring (e.g.
-# an "Author"-named view, or any name containing "health"/"static") are not
-# accidentally exempted from enforcement.
+# for every auth backend), the SPA profile page and the APIs its password
+# change modal needs (the current-user API it submits to and the CSRF token
+# endpoint), the legacy user-info-edit view, static assets, and the health
+# blueprint. We match the *view-class* component (the part before the dot)
+# exactly against the allow-list below rather than doing a substring search, so
+# unrelated endpoints that merely share a substring (e.g. an "Author"-named
+# view, or any name containing "health"/"static") are not accidentally exempted
+# from enforcement.
_EXEMPT_VIEW_CLASSES = frozenset(
{
"AuthDBView",
"AuthLDAPView",
"AuthOAuthView",
"AuthOIDView",
"AuthRemoteUserView",
- "ResetMyPasswordView",
- "ResetPasswordView",
+ "CurrentUserRestApi",
+ "SecurityRestApi",
Review Comment:
✅ **CodeAnt verified this suggestion was addressed in subsequent commits and
marked this thread resolved** as of `779f810`.
Replaced the broad `SecurityRestApi` exemption with an exact endpoint
allow-list, retaining only `SecurityRestApi.csrf_token` alongside the
profile-related endpoints.
<sub>If that's not right, unresolve this thread and CodeAnt will leave it
open.</sub>
<!-- codeant-auto-resolve-reply -->
##########
superset-frontend/src/features/userInfo/UserInfoModal.tsx:
##########
@@ -39,7 +39,7 @@ function UserInfoModal({
const requiredFields = isEditMode
? ['first_name', 'last_name']
- : ['password', 'confirm_password'];
+ : ['current_password', 'password', 'confirm_password'];
Review Comment:
✅ **CodeAnt verified this suggestion was addressed in subsequent commits and
marked this thread resolved** as of `779f810`.
Removed `current_password` from the required form fields and omitted it from
the request payload when blank, allowing accounts without a stored password to
set one.
<sub>If that's not right, unresolve this thread and CodeAnt will leave it
open.</sub>
<!-- codeant-auto-resolve-reply -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]