mikebridge opened a new pull request, #45002: URL: https://github.com/apache/superset/pull/45002
### SUMMARY Contextual access checks (chart viewers, native-filter value requests, dashboard member charts and multi-layer chart children for embedded guests) now match a chart or filter target on both the datasource's type and its id, rather than on the id alone or on object identity. Native filter targets without a type, or whose stored type is null, continue to refer to SQL datasets, and the optional guest-token `datasets` allowlist applies to SQL datasets only. Drill By applies the same type-and-id check to its source chart, and guest-token minting with a dataset allowlist checks only the SQL datasets the allowlist can grant. Authorized guests can read member charts on semantic views in the same way as on SQL datasets. The embedding docs describe the scope. Depends on #44987; please merge after it. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A (backend). ### TESTING INSTRUCTIONS - `pytest tests/unit_tests/security/typed_datasource_access_test.py tests/unit_tests/security/test_guest_token_dataset_allowlist.py tests/unit_tests/subjects/test_raise_for_access.py tests/unit_tests/security/manager_test.py` - Covers chart-viewer, native-filter (including legacy untyped and null-typed targets, and sort metrics), Drill By, guest member-chart and multi-layer child access, token minting, and the guest dataset allowlist, for both SQL datasets and semantic views, each allowed and denied. ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration - [ ] Introduces new feature or API - [ ] Removes existing feature or API Risk: low to medium. Access checks become stricter where a type did not match; authorized semantic-view member charts become readable by embedded guests. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
