EnxDev commented on code in PR #44645:
URL: https://github.com/apache/superset/pull/44645#discussion_r4103157495
##########
superset/models/helpers.py:
##########
@@ -3771,6 +3771,7 @@ def get_from_clause(
self.schema or default_schema or "",
statement,
exclude_dataset_id=self_id,
+ include_global_guest_rls=False,
Review Comment:
You're right, and it's the same class of gap. In the inner SQL only the
global guest rules are skipped (dataset-scoped guest rules and regular RLS
still apply), but the outer `org_id = 1` only narrows the rows the virtual
dataset exposes, so a scalar sub-query or a joined table in the virtual SQL
isn't scoped. This PR leaves that path as it was on master; the explicit
`False` just spells out the old default.
I'd rather not fix it here. Turning global rules back on for the whole inner
SQL brings back the double application #37395 removed, and breaks virtual
datasets whose inner tables don't have the column. The right shape is probably
to skip them only for the tables the outer filter actually covers, which needs
more thought with joins. I'll pick it up as a follow-up.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]