EnxDev opened a new pull request, #44645: URL: https://github.com/apache/superset/pull/44645
### SUMMARY When `ALLOW_ADHOC_SUBQUERY` is enabled, `validate_adhoc_subquery` rewrites each sub-query in an adhoc expression through `apply_rls`, so the tables it reads get their RLS predicates. `get_predicates_for_table` always called `get_sqla_row_level_filters(include_global_guest_rls=False)`, though, which drops guest-token rules that have no `dataset` key. Skipping those rules is correct for a virtual dataset's inner SQL, since the outer query on the virtual dataset already applies them (the double-application fix for #37359). An adhoc sub-query is different: the outer query's WHERE clause doesn't constrain it, so nothing applied the guest's clause-only rules to it. Dataset-scoped guest rules and regular Superset RLS rules were already applied correctly. The change: - `apply_rls` and `get_predicates_for_table` take an `include_global_guest_rls` flag. It defaults to `False`, so virtual datasets and SQL Lab keep their current behaviour. - `validate_adhoc_subquery` passes `True`. That covers adhoc metrics, columns, WHERE/HAVING and ORDER BY, plus stored expressions validated at query time, since they all go through this function. Users without a guest token are unaffected, because `get_guest_rls_filters` returns nothing for them. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A, backend only. ### TESTING INSTRUCTIONS Unit tests: ``` pytest tests/unit_tests/security/guest_rls_test.py tests/unit_tests/sql_lab_test.py tests/unit_tests/utils/rls_test.py tests/unit_tests/models/test_double_rls_virtual_dataset.py ``` The two new tests in `guest_rls_test.py` send a guest token through `validate_adhoc_subquery`. One has only a global rule; the other has a global rule plus a dataset-scoped rule. Both check that every predicate ends up inside the sub-query. They fail on master and pass with this change. The existing test asserting that `get_predicates_for_table` excludes global guest rules by default still passes. Manual check: 1. Enable `EMBEDDED_SUPERSET` and `ALLOW_ADHOC_SUBQUERY`. 2. Create a guest token for an embedded dashboard with a rule that has only a `clause` (no `dataset`). 3. Request chart data with an adhoc SQL metric that contains a sub-query over the chart's table. 4. Check the generated SQL (`result_type: "query"`): the guest clause now appears inside the sub-query as well as in the outer WHERE. ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [x] Required feature flags: `EMBEDDED_SUPERSET`, `ALLOW_ADHOC_SUBQUERY` - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Migration is atomic, supports rollback & is backwards-compatible - [ ] Confirm DB migration upgrade and downgrade tested - [ ] Runtime estimates and downtime expectations provided - [ ] Introduces new feature or API - [ ] Removes existing feature or API 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
