bito-code-review[bot] commented on PR #44705:
URL: https://github.com/apache/superset/pull/44705#issuecomment-5846202260
<!-- Bito Reply -->
The flagged issue is correct. When `impersonate_user` is enabled, the
current implementation filters out shared credentials from `connect_args` but
does not explicitly ensure that the user's `access_token` is preserved if it
was only provided via `encrypted_extra` (and thus not yet in
`params['connect_args']`).
To resolve this, you should ensure the user's token is explicitly merged
into the `connect_args` before the filtering logic runs, or ensure the filter
logic accounts for the token's source. Given the existing logic in
`update_params_from_encrypted_extra`, you can ensure the `access_token` is
present in the `connect_args` dictionary before the filtering step.
Would you like me to fetch all other comments on this PR to validate and
implement fixes for them as well?
**superset/db_engine_specs/databricks.py**
```
if database.impersonate_user:
# Ensure the user's token is available for the filter
if "access_token" not in connect_args and "access_token" in
secure_connect_args:
connect_args["access_token"] =
secure_connect_args.pop("access_token")
connect_args = {
key: value
for key, value in connect_args.items()
if key == "access_token"
or key not in DATABRICKS_SHARED_CREDENTIAL_CONNECT_ARGS
}
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]