EnxDev commented on code in PR #44645:
URL: https://github.com/apache/superset/pull/44645#discussion_r4103037729
##########
superset/models/helpers.py:
##########
@@ -511,8 +511,15 @@ def validate_adhoc_subquery(
)
)
- # enforce RLS rules in any relevant tables
- rls_applied = apply_rls(database, catalog, default_schema,
parsed_statement)
+ # Enforce RLS rules in any relevant tables. Global guest rules are
included
+ # because the outer query's WHERE clause does not constrain a
sub-query.
+ rls_applied = apply_rls(
+ database,
+ catalog,
+ default_schema,
+ parsed_statement,
+ include_global_guest_rls=True,
Review Comment:
Yes, that's intended. A rule without `dataset` already applies to every
dataset, so a chart whose own dataset lacks `org_id` fails the same way on the
outer query today. The sub-query was the one place the rule silently didn't
apply, and there it read rows the token was meant to exclude, so failing closed
is the fix. Token issuers who have lookup tables without the column can set
`dataset` on the rule to target only the datasets that have it. Agreed it's a
visible change though, so I added an UPDATING.md entry in b4156dd66c covering
it and the workaround.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]