sadpandajoe commented on code in PR #44101:
URL: https://github.com/apache/superset/pull/44101#discussion_r4153928930
##########
superset/views/core.py:
##########
@@ -797,6 +797,34 @@ def file_handler(self) -> FlaskResponse:
return self.render_app_template(extra_bootstrap_data=payload)
+ @has_access
Review Comment:
Existing custom roles are not granted the new `can_extension_view`
permission by role sync, so a user who can already load extensions can see the
Settings entry but gets a 403 on full navigation or refresh, even though in-app
navigation works. Should this shell use the same login-only gate as `welcome`,
or should the client honor the new permission too?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]