mikebridge commented on code in PR #44851: URL: https://github.com/apache/superset/pull/44851#discussion_r4200603749
########## superset/commands/semantic_layer/refresh_metadata.py: ########## @@ -0,0 +1,341 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +from __future__ import annotations + +from collections.abc import Callable, Iterator +from contextlib import contextmanager +from datetime import datetime, timezone +from typing import Any, Literal +from uuid import UUID + +from flask import current_app, g, has_request_context, Request, request +from flask_appbuilder.security.sqla.models import User +from sqlalchemy.orm import Session +from superset_core.semantic_layers.layer import SemanticLayer as SemanticLayerABC +from superset_core.semantic_layers.metadata import ( + MetadataRefreshError, + MetadataRefreshResult, +) +from superset_core.semantic_layers.view import SemanticView as SemanticViewABC + +from superset import cache_manager, security_manager +from superset.commands.base import BaseCommand +from superset.commands.semantic_layer.exceptions import ( + SemanticLayerForbiddenError, + SemanticLayerNotFoundError, + SemanticViewNotFoundError, +) +from superset.commands.utils import current_user_can_modify_object +from superset.coordination.deadline_backend import DeadlineRedisBackend +from superset.daos.semantic_layer import SemanticViewDAO +from superset.exceptions import SupersetSecurityException +from superset.extensions import db +from superset.semantic_layers.cache_inspection import CacheEntryInfo, inspect_data_cache +from superset.semantic_layers.metadata import ScopedMetadataStore +from superset.semantic_layers.metadata_binding import ( + connection_metadata_scope, + metadata_refresh_enabled, + operation_deadline, + participates, +) +from superset.semantic_layers.metadata_cache import ( + compatibility_identity, + CompatibilityIdentity, +) +from superset.semantic_layers.models import SemanticLayer, SemanticView +from superset.semantic_layers.registry import registry +from superset.utils import json + + +def authorize_metadata_refresh(view: SemanticView) -> None: + """Share one server policy between the affordance and direct mutation.""" + if not metadata_refresh_enabled(): + raise SemanticViewNotFoundError() + user: User | None = getattr(g, "user", None) + if ( + user is None + or user.is_anonymous + or getattr(user, "is_guest_user", False) + or not user.is_active + ): + raise SemanticLayerForbiddenError() + if not all( + security_manager.can_access(action, resource) + for action, resource in ( + ("can_read", "SemanticView"), + ("can_read", "SemanticLayer"), + ("can_write", "SemanticLayer"), + ) + ): + raise SemanticLayerForbiddenError() + layer: SemanticLayer | None = view.semantic_layer + if layer is None: + raise SemanticLayerNotFoundError() + try: + view.raise_for_access() + layer.raise_for_access() + except SupersetSecurityException: + raise SemanticLayerForbiddenError() from None + if not current_user_can_modify_object(layer): + raise SemanticLayerForbiddenError() + if layer.type not in registry: + raise MetadataRefreshError("unsupported") + if not participates(layer): + raise MetadataRefreshError("unsupported") + connection_metadata_scope(layer) + + +def can_refresh_metadata(view: SemanticView) -> bool: + """Project policy without constructing a provider or consulting its catalog.""" + try: + authorize_metadata_refresh(view) + except ( + SemanticViewNotFoundError, + SemanticLayerNotFoundError, + SemanticLayerForbiddenError, + MetadataRefreshError, + ): + return False + return True + + +def view_binding(view: SemanticView) -> tuple[str, str, str]: + """Capture immutable provider selection, independent of Details drafts.""" + return ( + str(view.semantic_layer_uuid), + view.name, + json.dumps(json.loads(view.configuration), sort_keys=True), + ) + + +@contextmanager +def fresh_refresh_authority(session: Session) -> Iterator[None]: + """Run existing policy against persisted authority without ending request work. + + Security-manager and subject helpers use the request-scoped session and + principal. Rebind those only for this guard so they cannot reuse an earlier + repeatable-read snapshot or cached role membership. The supplied session + owns no writes; the caller closes it. Always restore the request's objects. + """ + original_user: User = g.user + original_session: Session = db.session() + had_login_user: bool = hasattr(g, "_login_user") + original_login_user: Any = getattr(g, "_login_user", None) + if original_user.is_anonymous or getattr(original_user, "is_guest_user", False): + raise SemanticLayerForbiddenError() + user: User | None = session.get(security_manager.user_model, original_user.id) + if user is None or not user.is_active: + raise SemanticLayerForbiddenError() + current_request: Request | None = ( + request._get_current_object() if has_request_context() else None + ) + had_subject_cache: bool = current_request is not None and hasattr( + current_request, "_user_subject_ids" + ) + original_subject_cache: dict[int, list[int]] | None = getattr( + current_request, "_user_subject_ids", None + ) + try: + if current_request is not None: + current_request._user_subject_ids = {} + db.session.registry.set(session) + g.user = user + g._login_user = user + with session.no_autoflush: + yield + finally: + if current_request is not None: + if had_subject_cache: + current_request._user_subject_ids = original_subject_cache + else: + current_request.__dict__.pop("_user_subject_ids", None) + g.user = original_user + if had_login_user: + g._login_user = original_login_user + else: + g.pop("_login_user", None) + db.session.registry.set(original_session) + + +def guarded_store( + view: SemanticView, *, before_publish: Callable[[], None] +) -> ScopedMetadataStore: + """Bind command-specific fresh authority to the unchanged host store contract.""" + deadline: float = operation_deadline() + config: Any = current_app.config.get("DISTRIBUTED_COORDINATION_CONFIG") + if not isinstance(config, dict): + raise MetadataRefreshError("unavailable") + try: + backend: DeadlineRedisBackend = DeadlineRedisBackend(config, deadline=deadline) + except ValueError: + raise MetadataRefreshError("configuration") from None + return ScopedMetadataStore( + backend, + connection_metadata_scope(view.semantic_layer), + deadline=deadline, Review Comment: Fixed in `925580bc`. The command factory passes `SEMANTIC_LAYER_METADATA_SNAPSHOT_TTL_SECONDS` to the store just like ordinary discovery. Tests build the real factory and check both catalog publication and compatibility-generation invalidation at 10, 60 and 3600 seconds; each previously used 300 seconds and now respects the configured expiry. ########## superset-frontend/src/explore/components/ExploreViewContainer/ExploreViewContainer.test.tsx: ########## @@ -860,6 +860,79 @@ function setupTableChartControlPanel() { }); } +test('clearing a singleton metric refreshes semantic compatibility after metadata sync', async () => { + const fetchCompatibilitySpy = jest.spyOn( + exploreActions, + 'fetchCompatibility', + ); + const endpoint = 'path:/api/v1/datasource/semantic_view/7/compatible'; + fetchMock.post(endpoint, { + result: { + compatible_metrics: ['metric_a', 'metric_b'], + compatible_dimensions: [], + }, + }); + const initialState = { + ...reduxState, + explore: { + ...reduxState.explore, + datasource: { + ...reduxState.explore.datasource, + id: 7, + type: 'semantic_view', + }, + form_data: { + datasource: '7__semantic_view', + viz_type: VizType.BigNumberTotal, + metric: 'metric_a', + }, + controls: { + datasource: { value: '7__semantic_view' }, + viz_type: { value: VizType.BigNumberTotal }, + metric: { value: 'metric_a' }, + }, + }, + }; + const store = createStore(initialState, reducerIndex); + renderWithRouter({ initialState, store }); + await waitFor(() => + expect(store.getState()).toMatchObject({ + explore: { compatibility: { status: 'verified' } }, + }), + ); + // Model the completed sync answer: metric B cannot combine with metric A. + act(() => { + store.dispatch( + exploreActions.setCompatibility({ + status: 'verified', + metrics: ['metric_a'], + dimensions: [], + }), + ); + }); + fetchCompatibilitySpy.mockClear(); Review Comment: Added the mount assertion in `58e8cbb1`: fetchCompatibility must receive ["metric_a"] before the spy is cleared, followed by the existing empty-selection assertion after clearing the singleton metric. Omitting the singleton input can no longer satisfy this test. ########## superset-frontend/src/explore/actions/exploreActions.ts: ########## @@ -281,6 +290,63 @@ export function syncDatasourceMetadata(datasource: Dataset) { return { type: SYNC_DATASOURCE_METADATA, datasource }; } +export const SYNC_SEMANTIC_METADATA = 'explore/SYNC_SEMANTIC_METADATA'; +/** Rebuild metadata-derived controls without recording a chart edit. */ +export function syncSemanticMetadata( + datasource: Dataset, + formData: QueryFormData, +): { + type: typeof SYNC_SEMANTIC_METADATA; + datasource: Dataset; + formData: QueryFormData; +} { + return { type: SYNC_SEMANTIC_METADATA, datasource, formData }; +} + +/** Refresh the active view's metadata without saving or running the chart. */ +export function refreshSemanticMetadata( + viewId: number, + sessionIsCurrent: () => boolean, +) { + return async ( + dispatch: Dispatch, + getState: () => Pick<ExplorePageState, 'explore'>, + ) => { + const isActiveDatasource = () => { + const { datasource } = getState().explore; + return ( + Number(datasource.id) === viewId && + String(datasource.type) === 'semantic_view' + ); + }; + const isCurrent = () => sessionIsCurrent() && isActiveDatasource(); + if (!isCurrent()) return; + // A pre-sync compatibility response cannot replace a post-sync answer. + compatibilityRequestSeq += 1; Review Comment: Fixed in `58e8cbb1`. A failed metadata GET or a session closing during that GET settles the retired loading request as failed, only while the request sequence and active datasource still belong to it. Tests start with an outstanding compatibility POST, exercise both exits, reject its late answer, and verify a newer compatibility request is not overwritten. ########## superset-frontend/src/features/semanticViews/SemanticViewEditModal.tsx: ########## @@ -188,15 +203,87 @@ export default function SemanticViewEditModal({ }); addSuccessToast?.(t('Semantic view updated')); onSave(); - onHide(); + if (isCurrent()) handleHide(); } catch (error) { const clientError = await getClientErrorObject(error); addDangerToast?.( clientError.error || t('An error occurred while saving the semantic view'), ); } finally { - setSaving(false); + if (isCurrent()) { + busy.current = false; + setSaving(false); + } + } + }; + + const reloadFields = async ( + viewId: number, + changed: boolean, + isCurrent: () => boolean, + ) => { + setSyncState({ status: 'reloading', changed }); + try { + const { json } = await SupersetClient.get({ + endpoint: `/api/v1/semantic_view/${viewId}/structure`, + }); + if (!isCurrent()) return; + setStructure(json.result); + await onMetadataSync?.(isCurrent); Review Comment: Added the callback-rejection regression in `58e8cbb1`. After publication and a successful structure GET, onMetadataSync rejects; the modal shows Reload fields without claiming success. Retrying reload invokes the callback again and succeeds while the refresh POST count stays at one. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
