EnxDev commented on code in PR #44849:
URL: https://github.com/apache/superset/pull/44849#discussion_r4163435214


##########
superset/semantic_layers/api.py:
##########
@@ -196,8 +233,22 @@ class SemanticViewRestApi(BaseSupersetModelRestApi):
     method_permission_name = {
         **MODEL_API_RW_METHOD_PERMISSION_MAP,
         "structure": "read",
+        "refresh_metadata": "read",

Review Comment:
   The three POST mutations map to `read`, so `@protect()` lets any role with 
can_read on SemanticView through. The only write gate is then the `can_write` 
check inside `authorize_metadata_refresh`, and the FAB permission matrix lists 
these routes as read-only.
   
   Was `read` deliberate, so layer editors don't also need can_write on 
SemanticView? If not, mapping `refresh_metadata` and the two `invalidate_*` 
routes to `write` would make the route gate match what they do.



##########
superset/common/query_context_processor.py:
##########
@@ -472,7 +479,18 @@ def _annotation_cache_context(self, query_obj: 
QueryObject) -> dict[str, Any]:
                 if annotation_datasource
                 else None
             )
-        return {"user_id": get_user_id(), "source_rls": source_rls}
+            metadata_datasource: Datasource | None = (
+                chart.resolved_datasource if chart else None
+            )
+            if isinstance(metadata_datasource, SemanticView):
+                token: str | None = metadata_datasource.metadata_cache_token

Review Comment:
   This resolves the annotation source view's implementation while building the 
host chart's cache key. If that provider fails (`upstream`, `deadline`, 
`unavailable`), the whole host chart fails, even when its result is already 
cached. Before this change, a warm entry was served without touching the 
annotation source at all.
   
   Could we read the token here without discovery, e.g. a `peek()` of the 
stored snapshot like the inspection path does, or fall back to a key that 
simply misses when it raises?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to