sadpandajoe commented on code in PR #44101:
URL: https://github.com/apache/superset/pull/44101#discussion_r4171325980


##########
tests/integration_tests/core_tests.py:
##########
@@ -953,6 +953,35 @@ def test_dashboard_permalink_returns_404_for_missing_state(
         assert resp.status_code == 404
         assert "Location" not in resp.headers
 
+    def test_extension_view_anonymous_redirects_to_login(self):
+        resp = self.client.get("/extensions/view/my-ext.settings")
+
+        expected_url = "/login/?next=%2Fextensions%2Fview%2Fmy-ext.settings"
+
+        assert resp.status_code == 302
+        assert resp.headers["Location"] == expected_url
+
+    def test_extension_view_authenticated_returns_spa_shell(self):
+        self.login(ADMIN_USERNAME)
+
+        resp = self.client.get("/extensions/view/my-ext.settings")
+
+        assert resp.status_code == 200
+        assert b'id="app"' in resp.data
+
+    def 
test_extension_view_gamma_without_extension_permission_returns_spa_shell(
+        self,
+    ):
+        # Gamma isn't granted the FAB-generated `can_extension_view`

Review Comment:
   This Gamma fixture does not protect the custom-role regression: CI runs role 
sync, which would grant Gamma `can_extension_view` if `@has_access` were 
restored, leaving this test green while existing custom-role users get 403s 
again. Could we use a custom role, assert it lacks that permission, and then 
assert the direct request returns the SPA shell?



##########
superset-frontend/src/pages/ExtensionView/index.tsx:
##########
@@ -0,0 +1,62 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+import { useParams } from 'react-router-dom';
+import { t } from '@apache-superset/core/translation';
+import SubMenu, { SubMenuProps } from 'src/features/home/SubMenu';
+import { useResolveView } from 'src/core/views';
+
+/**
+ * Generic full-page host for a single extension-registered view, reached at
+ * `/extensions/view/:viewId+`. Extensions cannot render their own views
+ * directly (`resolveView`/`useResolveView` are host-internal, not part of
+ * the public `@apache-superset/core` SDK) -- they register a view at
+ * `GlobalLocations.settings.panel` and a matching command at
+ * `GlobalLocations.settings.menu` whose callback navigates here, and the
+ * host resolves and renders it.
+ *
+ * Uses the reactive `useResolveView`, not the plain `resolveView`: this
+ * page is reachable by a direct/full navigation (a bookmark, a page
+ * refresh, or an extension's own menu command falling back to
+ * `window.location.assign` in the absence of an SDK-level SPA-navigation
+ * primitive), and the providing extension's own code loads asynchronously
+ * -- a non-reactive resolve would permanently commit to the "could not be
+ * loaded" placeholder from before that load finishes.
+ */
+const ExtensionView = () => {
+  const { viewId } = useParams<{ viewId: string }>();
+
+  const menuData: SubMenuProps = {
+    name: t('Extension'),
+  };
+
+  const resolved = useResolveView(viewId ?? '');

Review Comment:
   A registered `my-ext/settings` view never resolves when its command 
navigates to `/extensions/view/my-ext%2Fsettings` using `encodeURIComponent`: 
the router preserves `%2F`, so this lookup uses a different registry key. Could 
we define a matching URL encoding/decoding contract and cover the encoded route 
as well as the literal-slash case?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to