madhushreeag commented on code in PR #44365: URL: https://github.com/apache/superset/pull/44365#discussion_r4198130757
########## superset/security/login_token.py: ########## @@ -0,0 +1,290 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +"""One-time login tokens for establishing a session inside an iframe. + +An SSO redirect flow cannot run inside an iframe: identity providers commonly +refuse to be framed, and the redirect chain depends on cookies that browsers +treat as third-party in an embedded context. A parent application that already +holds a trustworthy proof of the user's identity uses these tokens to turn that +proof into an ordinary Superset session in two steps: + +1. its backend mints a token, presenting a credential that an operator-supplied + resolver validates (server-to-server, so the credential never reaches the + browser), and +2. the browser navigates the iframe to the consume endpoint, which exchanges the + token for a session cookie. + +The token is an opaque handle to a short-lived server-side record; no identity +data travels in the URL. +""" + +from __future__ import annotations + +import logging +import re +from datetime import datetime, timedelta +from typing import Any, Callable, cast, TypedDict +from uuid import UUID, uuid4 + +from flask import current_app, Request + +from superset.daos.key_value import KeyValueDAO Review Comment: The documented example in `superset_config.py` fails startup with `Exception: App not initialized yet` at `key_value/models.py` imports `superset.models.helpers`, which drags in `models.core` and builds `encrypted_field_factory` columns at class-definition time. `KeyValueDAO` and `KeyValueEntry` now import inside `mint`/`consume`, while `key_value.types` and `key_value.utils` stay at module scope since neither pulls in a model - so the documented import path keeps working rather than moving the type and leaving a stale example. Guarded by `test_module_is_importable_without_an_initialized_app`, which imports in a subprocess because in-process the models are already loaded by the time the suite runs. mutation-checked by re-adding the module-scope import. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
