aminghadersohi commented on PR #44695: URL: https://github.com/apache/superset/pull/44695#issuecomment-5902065056
@rebenitez1802 Thanks for the review. Explicit decision on the delegation/create-flow note, implemented in 4954f82e9910ecc6d9ca0ae13821f6c95537582a: keep service-account validation and queries on the service-account identity, on both create and edit; do not move the modal's forced impersonation default ahead of validation. EnxDev's query-path observation changes the premise of the two-step workaround: `Database._get_sqla_engine` applies impersonation before encrypted-extra processing (`superset/models/core.py:685-694`), and the resulting `connect_args.adapter_kwargs` replaces the URL-derived subject (`superset/db_engine_specs/gsheets.py:380-392`). The new real-engine/DBAPI regression proves that even an enabled flag does not send a delegated subject on this credential path. Creating an empty connection and then adding an admin-only sheet therefore would not make queries work as that admin. Private sheets need to be shared with the service account; this is documented in `docs/admin_docs/configuration/google-sheets.mdx:25-36`. The optional `datetime.time` and edit-credential coverage are added, and the timezone-aware upload-as-text caveat is documented. Nullable-Int64 coercion and the DataFrame/list variable naming nit are left unchanged to keep this follow-up focused. All 63 GSheets unit tests and changed-file pre-commit (including mypy) pass. No frontend files changed; live Google/browser testing was not performed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
