mikebridge opened a new pull request, #44905: URL: https://github.com/apache/superset/pull/44905
### SUMMARY Deleting a semantic layer left its views' `datasource_access` permissions and role grants behind when the views were not loaded in the session, because the cleanup depended on per-view ORM delete events. Cleanup now runs in a layer `before_delete` hook on the connection, so it does not depend on whether the views are loaded, and it happens in the same transaction as the delete. A permission that is still in use is kept. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A (backend cleanup on delete). ### TESTING INSTRUCTIONS - `pytest tests/unit_tests/semantic_layers/models_test.py` - New tests delete a layer with its views loaded and unloaded and assert the view permissions and role grants are gone; they fail on master in the unloaded case. Further tests assert that a permission still in use survives both a view delete and a layer delete. - Not covered: concurrent deletes, and query cost on a layer with a very large number of views. ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Introduces new feature or API - [ ] Removes existing feature or API 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
