mikebridge opened a new pull request, #45034:
URL: https://github.com/apache/superset/pull/45034

   ### SUMMARY
   
   The scheduled soft-delete purge removed a purged dataset's 
`datasource_access` permission-view unconditionally. Since #44905, a semantic 
view can share that permission name, and the ORM delete path keeps the 
permission while another owner still uses it. The purge path did not, so 
purging a soft-deleted dataset could revoke a semantic view's role grants.
   
   - The purge cascade now uses the same ownership check as the ORM path. The 
helper from #44905 is generalised (`_semantic_view_perm_owned_elsewhere` → 
`_datasource_perm_owned_elsewhere`, accepting `None` when no view is being 
deleted).
   - The permission-view is deleted only when no remaining dataset or semantic 
view uses the name; other role grants are untouched.
   - The probe runs on the purge session's connection after the parent row is 
deleted, so it never matches the dataset being purged. Its cost is two `LIMIT 
1` queries per purged dataset, bounded by the purge cap.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A (backend).
   
   ### TESTING INSTRUCTIONS
   
   `pytest tests/integration_tests/deletion_retention/purge_tests.py`:
   
   - a dataset and a semantic view share a permission name; the dataset is 
soft-deleted and purged; the view's role grant survives (fails before this 
change);
   - an unshared dataset's permission is still removed.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue
   - [ ] Required feature flags
   - [ ] Changes UI
   - [ ] Includes DB Migration
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   Before this leaves draft: `dataset_after_delete` should use the same helper 
rather than its own inline query, plus a test for two datasets sharing a name 
purged in one run.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to