bito-code-review[bot] commented on PR #44796:
URL: https://github.com/apache/superset/pull/44796#issuecomment-5892541871
<!-- Bito Reply -->
The flagged issue is correct. The current implementation only checks if
`WEBSOCKET_ENABLE` is set, but it fails to verify if the principal has the
necessary `can_read` permission on the `Realtime` resource, leading to a false
success report when the user lacks authorization.
To resolve this, you should update `_publish_filters_applied` in
`superset/mcp_service/dashboard/tool/apply_dashboard_filters.py` to include a
permission check using `security_manager.can_read_permission` or similar
authorization logic before returning `True`.
Would you like me to implement this permission check and check the rest of
the PR comments for you?
**superset/mcp_service/dashboard/tool/apply_dashboard_filters.py**
```
if not current_app.config.get("WEBSOCKET_ENABLE"):
return False
# Add permission check here:
# if not security_manager.can_read_permission("Realtime", ...):
# return False
if not CoordinationService.is_backend_defined():
return False
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]