EnxDev opened a new pull request, #44645:
URL: https://github.com/apache/superset/pull/44645

   ### SUMMARY
   
   When `ALLOW_ADHOC_SUBQUERY` is enabled, `validate_adhoc_subquery` rewrites 
each sub-query in an adhoc expression through `apply_rls`, so the tables it 
reads get their RLS predicates. `get_predicates_for_table` always called 
`get_sqla_row_level_filters(include_global_guest_rls=False)`, though, which 
drops guest-token rules that have no `dataset` key.
   
   Skipping those rules is correct for a virtual dataset's inner SQL, since the 
outer query on the virtual dataset already applies them (the double-application 
fix for #37359). An adhoc sub-query is different: the outer query's WHERE 
clause doesn't constrain it, so nothing applied the guest's clause-only rules 
to it. Dataset-scoped guest rules and regular Superset RLS rules were already 
applied correctly.
   
   The change:
   
   - `apply_rls` and `get_predicates_for_table` take an 
`include_global_guest_rls` flag. It defaults to `False`, so virtual datasets 
and SQL Lab keep their current behaviour.
   - `validate_adhoc_subquery` passes `True`. That covers adhoc metrics, 
columns, WHERE/HAVING and ORDER BY, plus stored expressions validated at query 
time, since they all go through this function.
   
   Users without a guest token are unaffected, because `get_guest_rls_filters` 
returns nothing for them.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A, backend only.
   
   ### TESTING INSTRUCTIONS
   
   Unit tests:
   
   ```
   pytest tests/unit_tests/security/guest_rls_test.py 
tests/unit_tests/sql_lab_test.py tests/unit_tests/utils/rls_test.py 
tests/unit_tests/models/test_double_rls_virtual_dataset.py
   ```
   
   The two new tests in `guest_rls_test.py` send a guest token through 
`validate_adhoc_subquery`. One has only a global rule; the other has a global 
rule plus a dataset-scoped rule. Both check that every predicate ends up inside 
the sub-query. They fail on master and pass with this change. The existing test 
asserting that `get_predicates_for_table` excludes global guest rules by 
default still passes.
   
   Manual check:
   
   1. Enable `EMBEDDED_SUPERSET` and `ALLOW_ADHOC_SUBQUERY`.
   2. Create a guest token for an embedded dashboard with a rule that has only 
a `clause` (no `dataset`).
   3. Request chart data with an adhoc SQL metric that contains a sub-query 
over the chart's table.
   4. Check the generated SQL (`result_type: "query"`): the guest clause now 
appears inside the sub-query as well as in the outer WHERE.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [x] Required feature flags: `EMBEDDED_SUPERSET`, `ALLOW_ADHOC_SUBQUERY`
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to