bito-code-review[bot] commented on PR #44796:
URL: https://github.com/apache/superset/pull/44796#issuecomment-5892541871

   <!-- Bito Reply -->
   The flagged issue is correct. The current implementation only checks if 
`WEBSOCKET_ENABLE` is set, but it fails to verify if the principal has the 
necessary `can_read` permission on the `Realtime` resource, leading to a false 
success report when the user lacks authorization.
   
   To resolve this, you should update `_publish_filters_applied` in 
`superset/mcp_service/dashboard/tool/apply_dashboard_filters.py` to include a 
permission check using `security_manager.can_read_permission` or similar 
authorization logic before returning `True`.
   
   Would you like me to implement this permission check and check the rest of 
the PR comments for you?
   
   **superset/mcp_service/dashboard/tool/apply_dashboard_filters.py**
   ```
   if not current_app.config.get("WEBSOCKET_ENABLE"):
               return False
           # Add permission check here:
           # if not security_manager.can_read_permission("Realtime", ...):
           #     return False
           if not CoordinationService.is_backend_defined():
               return False
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to