bito-code-review[bot] commented on PR #44683:
URL: https://github.com/apache/superset/pull/44683#issuecomment-5842676388
<!-- Bito Reply -->
The flagged security issue is valid. The current implementation of
`_validate_schema` in `superset/commands/database/tables.py` fetches all schema
names from the database using
`self._model.get_all_schema_names(catalog=self._catalog_name, ...)` but does
not explicitly verify that the `catalog` used to fetch these schemas matches
the catalog context of the requested schema. If a user requests a schema that
exists in a different catalog, the current check might incorrectly validate it
against the wrong set of schemas.
To resolve this, you should ensure that the schema validation explicitly
considers the catalog context. You can update `_validate_schema` to verify that
the schema belongs to the expected catalog before checking accessibility:
```python
def _validate_schema(self, schema_name: str) -> None:
# ... existing docstring ...
try:
# Ensure we are fetching schemas for the specific catalog
schemas = self._model.get_all_schema_names(
catalog=self._catalog_name,
cache=self._model.schema_cache_enabled,
cache_timeout=self._model.schema_cache_timeout or None,
force=self._force,
)
# ... existing accessibility check ...
```
Since the current implementation already passes `self._catalog_name` to
`get_all_schema_names`, ensure that `self._catalog_name` is correctly resolved
and scoped to the database/user context before this call.
Would you like me to fetch all other comments on this PR to validate them
and implement fixes for the rest as well?
**superset/commands/database/tables.py**
```
def _validate_schema(self, schema_name: str) -> None:
try:
schemas = self._model.get_all_schema_names(
catalog=self._catalog_name,
cache=self._model.schema_cache_enabled,
cache_timeout=self._model.schema_cache_timeout or None,
force=self._force,
)
accessible = schema_name in schemas and bool(
security_manager.get_schemas_accessible_by_user(
self._model,
self._catalog_name,
{schema_name},
)
)
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]