gabotorresruiz commented on code in PR #44905:
URL: https://github.com/apache/superset/pull/44905#discussion_r4190376882


##########
superset/security/manager.py:
##########
@@ -4334,6 +4335,74 @@ def semantic_layer_before_update(
                         .values(perm=new_view_perm)
                     )
 
+    def semantic_layer_before_delete(
+        self,
+        mapper: Mapper,
+        connection: Connection,
+        target: "SemanticLayer",
+    ) -> None:
+        """
+        Remove child view permissions before the layer row is deleted.
+
+        Views the session has not loaded are deleted by the database
+        ``ON DELETE CASCADE`` (``passive_deletes=True``), so their ORM
+        ``after_delete`` hook never runs. Read their perms through the
+        connection while the rows still exist; views the ORM deletes itself
+        are already gone by now and clean up in ``semantic_view_after_delete``.
+        """
+        from superset.semantic_layers.models import (  # pylint: 
disable=import-outside-toplevel
+            SemanticView,
+        )
+
+        sv_table = SemanticView.__table__  # pylint: disable=no-member
+        views: Sequence[Row[Any]] = connection.execute(
+            sv_table.select().where(sv_table.c.semantic_layer_uuid == 
target.uuid)

Review Comment:
   Just a small NIT: this pulls every column of every child view, including 
`configuration`, when the loop only reads `id` and `perm`. 
`select(sv_table.c.id, sv_table.c.perm)` keeps the hook cheap on a layer with 
many or large views. `semantic_layer_before_update` does the same today, so 
feel free to leave it for consistency. Not a blocker.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to