msyavuz commented on code in PR #44645:
URL: https://github.com/apache/superset/pull/44645#discussion_r4103023497
##########
superset/models/helpers.py:
##########
@@ -511,8 +511,15 @@ def validate_adhoc_subquery(
)
)
- # enforce RLS rules in any relevant tables
- rls_applied = apply_rls(database, catalog, default_schema,
parsed_statement)
+ # Enforce RLS rules in any relevant tables. Global guest rules are
included
+ # because the outer query's WHERE clause does not constrain a
sub-query.
+ rls_applied = apply_rls(
+ database,
+ catalog,
+ default_schema,
+ parsed_statement,
+ include_global_guest_rls=True,
Review Comment:
A global guest clause like `org_id = 1` will now be injected into any
sub-query table that resolves to a dataset, including lookup tables without an
`org_id` column. Is it intended that embedded charts using such sub-queries
start failing with column-not-found? Fails closed, but it's a visible change
for existing embedded dashboards, probably worth a note in UPDATING.md.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]