sfirke commented on code in PR #44243:
URL: https://github.com/apache/superset/pull/44243#discussion_r4145444018


##########
docs/admin_docs/configuration/cache.mdx:
##########
@@ -311,21 +311,35 @@ CACHE_WARMUP_EXECUTORS = [FixedExecutor("admin")]
 Use a dedicated read-only service account here rather than a personal admin 
account, so that
 thumbnail rendering and cache warmup tasks don't fail if a specific user's 
credentials change.
 
-Additional Selenium WebDriver configuration can be set using 
`WEBDRIVER_CONFIGURATION`. You can
-implement a custom function to authenticate Selenium. The default function 
uses the `flask-login`
-session cookie. Here's an example of a custom function signature:
+Thumbnails are rendered with Playwright and a headless Chromium browser. Extra 
Chromium launch
+arguments can be set using `WEBDRIVER_OPTION_ARGS`. You can implement a custom 
function to
+authenticate the Playwright browser context. The default function uses the 
`flask-login` session
+cookie. Here's an example of a custom function signature:
 
 ```python
-def auth_driver(driver: WebDriver, user: "User") -> WebDriver:
-    pass
+from __future__ import annotations

Review Comment:
   Good catch. I switched to quoted annotations and kept the `TYPE_CHECKING` 
guard, so the snippet can be pasted anywhere and still loads without Playwright 
installed.
   
   ---
   🤖 _Drafted by Claude Code, reviewed and approved by @sfirke._



##########
docs/admin_docs/configuration/cache.mdx:
##########
@@ -311,21 +311,35 @@ CACHE_WARMUP_EXECUTORS = [FixedExecutor("admin")]
 Use a dedicated read-only service account here rather than a personal admin 
account, so that
 thumbnail rendering and cache warmup tasks don't fail if a specific user's 
credentials change.
 
-Additional Selenium WebDriver configuration can be set using 
`WEBDRIVER_CONFIGURATION`. You can
-implement a custom function to authenticate Selenium. The default function 
uses the `flask-login`
-session cookie. Here's an example of a custom function signature:
+Thumbnails are rendered with Playwright and a headless Chromium browser. Extra 
Chromium launch
+arguments can be set using `WEBDRIVER_OPTION_ARGS`. You can implement a custom 
function to
+authenticate the Playwright browser context. The default function uses the 
`flask-login` session
+cookie. Here's an example of a custom function signature:
 
 ```python
-def auth_driver(driver: WebDriver, user: "User") -> WebDriver:
-    pass
+from __future__ import annotations
+
+from typing import TYPE_CHECKING
+
+if TYPE_CHECKING:
+    from flask_appbuilder.security.sqla.models import User
+    from playwright.sync_api import BrowserContext
+
+
+def auth_browser_context(browser_context: BrowserContext, user: User) -> 
BrowserContext:
+    # Add cookies or headers that authenticate as `user`, then return the 
context.
+    return browser_context

Review Comment:
   Agreed. Setting `WEBDRIVER_AUTH_FUNC` skips the built-in cookie login 
entirely, so a placeholder that returns the context unchanged fails silently. 
The example now shows a concrete step, a bearer token added as a request 
header, with the token lookup as a named placeholder (`get_token_for_user`), so 
an unedited copy fails with a clear `NameError` instead of quietly sending 
unauthenticated requests. The text also states that this function replaces the 
default authentication.
   
   ---
   🤖 _Drafted by Claude Code, reviewed and approved by @sfirke._



##########
docs/admin_docs/configuration/cache.mdx:
##########
@@ -311,21 +311,35 @@ CACHE_WARMUP_EXECUTORS = [FixedExecutor("admin")]
 Use a dedicated read-only service account here rather than a personal admin 
account, so that
 thumbnail rendering and cache warmup tasks don't fail if a specific user's 
credentials change.
 
-Additional Selenium WebDriver configuration can be set using 
`WEBDRIVER_CONFIGURATION`. You can
-implement a custom function to authenticate Selenium. The default function 
uses the `flask-login`
-session cookie. Here's an example of a custom function signature:
+Thumbnails are rendered with Playwright and a headless Chromium browser. Extra 
Chromium launch
+arguments can be set using `WEBDRIVER_OPTION_ARGS`. You can implement a custom 
function to
+authenticate the Playwright browser context. The default function uses the 
`flask-login` session
+cookie. Here's an example of a custom function signature:
 
 ```python
-def auth_driver(driver: WebDriver, user: "User") -> WebDriver:
-    pass
+from __future__ import annotations
+
+from typing import TYPE_CHECKING
+
+if TYPE_CHECKING:
+    from flask_appbuilder.security.sqla.models import User
+    from playwright.sync_api import BrowserContext
+
+
+def auth_browser_context(browser_context: BrowserContext, user: User) -> 
BrowserContext:
+    # Add cookies or headers that authenticate as `user`, then return the 
context.
+    return browser_context
 ```
 
 Then on configuration:
 
 ```
-WEBDRIVER_AUTH_FUNC = auth_driver
+WEBDRIVER_AUTH_FUNC = auth_browser_context
 ```
 
+To replace the authentication logic entirely, subclass 
`superset.utils.machine_auth.MachineAuthProvider`,
+override `authenticate_browser_context()`, and set 
`MACHINE_AUTH_PROVIDER_CLASS` to your class.

Review Comment:
   Confirmed. The setting goes through `load_class_from_name`, and the default 
in `config.py` is a dotted string. I've applied your suggestion.
   
   ---
   🤖 _Drafted by Claude Code, reviewed and approved by @sfirke._



##########
docs/admin_docs/configuration/cache.mdx:
##########
@@ -241,7 +241,7 @@ FEATURE_FLAGS = {
 }
 ```
 
-By default thumbnails are rendered per user, and will fall back to the 
Selenium user for anonymous users.
+By default thumbnails are rendered as the user who requests them.

Review Comment:
   Good point. The old sentence covered this, and I dropped it along with the 
Selenium wording. One small correction: `get_executor()` does raise 
`ExecutorNotFoundError`, but the digest functions catch it and return `None`, 
so anonymous users get no thumbnail rather than an error. I added a sentence 
saying so, with an example of adding a `FixedExecutor` fallback to 
`THUMBNAIL_EXECUTORS`.
   
   ---
   🤖 _Drafted by Claude Code, reviewed and approved by @sfirke._



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to