codeant-ai-for-open-source[bot] commented on code in PR #44683:
URL: https://github.com/apache/superset/pull/44683#discussion_r4113535401
##########
superset/commands/database/tables.py:
##########
@@ -177,3 +175,40 @@ def validate(self) -> None:
self._model = cast(Database, DatabaseDAO.find_by_id(self._db_id))
if not self._model:
raise DatabaseNotFoundError()
+
+ self._catalog_name = self._catalog_name or
self._model.get_default_catalog()
+ if not self._model.db_engine_spec.supports_schemas:
+ self._schema_name = None
+
+ if self._schema_name:
+ self._validate_schema(self._schema_name)
+
+ def _validate_schema(self, schema_name: str) -> None:
+ """
+ Accept only a schema that the schemas endpoint would list for this
user.
+
+ The schema has to exist in the database and be accessible to the user,
+ otherwise ``DatabaseSchemaNotFoundError`` is raised before any table or
+ view lookup is run.
+ """
+ try:
+ schemas = self._model.get_all_schema_names(
+ catalog=self._catalog_name,
+ cache=self._model.schema_cache_enabled,
+ cache_timeout=self._model.schema_cache_timeout or None,
+ force=self._force,
+ )
+ accessible = schema_name in schemas and bool(
+ security_manager.get_schemas_accessible_by_user(
+ self._model,
+ self._catalog_name,
+ {schema_name},
+ )
Review Comment:
✅ **Customized review instruction saved!**
**Instruction:**
> Do not flag the schema-access check in this endpoint for cross-catalog
filtering differences; it intentionally matches GET /schemas/, while returned
tables and views are filtered through get_datasources_accessible_by_user. Treat
datasource_access catalog filtering as a separate security-manager concern.
**Applied to:**
- `superset/commands/database/tables.py`
---
💡 *To manage or update this instruction, visit: [CodeAnt AI
Settings](https://app.codeant.ai/org/settings/learnings)*
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]