eschutho opened a new pull request, #45065:
URL: https://github.com/apache/superset/pull/45065
### SUMMARY
When a user or group is created or updated, `superset/subjects/sync.py`
mirrors it into a `Subject` row. The user's email is copied into
`Subject.secondary_label` and `Subject.extra_search`. A group's description can
also end up in `Subject.secondary_label`. All of these `Subject` columns are
`String(255)`.
The source columns in Flask-AppBuilder are wider:
| Source field | FAB width | Subject column |
| --- | --- | --- |
| `User.email` | 320 | `secondary_label`, `extra_search` (255) |
| `Group.description` | 512 | `secondary_label` (255) |
So a valid user with an email longer than 255 characters, or a group with a
long description, makes the sync fail with a "value too long" error on
databases that enforce column lengths (e.g. PostgreSQL). The sync runs from
FAB's own `add_user()` / `update_user()` (and the group equivalents) through
signals, so this can block creating or editing the user or group itself, not
just custom provisioning flows.
**Fix:** a small `_fit()` helper in `sync.py` truncates each synced string
to the length of its target `Subject` column. It reads the width from the
column definition, so it stays correct if the column ever changes. It's applied
to the label, secondary label, and extra search values for both user and group
subjects. Labels already fit, but are clipped too as a guard. Values that fit
are stored unchanged. These fields are only used for display and search in
subject pickers, so a truncated copy is fine; the full value is still stored on
the FAB user/group.
I looked for an existing helper for this kind of DB-width mismatch and
didn't find one to reuse. The truncation helpers that exist are engine-specific
label truncation or for MCP response sizing.
### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
N/A
### TESTING INSTRUCTIONS
- `pytest tests/unit_tests/subjects/test_sync.py`
- A user with a 312-character email syncs, and the stored
`secondary_label` / `extra_search` are truncated to the column width. This is
tested on both the create and the update path.
- A group with a 512-character description syncs, and the stored
`secondary_label` is truncated. This is also tested on create and update.
- Short values are stored unchanged.
- The new truncation tests fail without the change to `sync.py`.
- To check manually on PostgreSQL: create a user whose email is longer than
255 characters (through the Users UI/API or `security_manager.add_user`).
Before this change the commit fails with `value too long for type character
varying(255)`. After it, the user is created and the subject shows the
truncated email.
### ADDITIONAL INFORMATION
- [ ] Has associated issue:
- [ ] Required feature flags:
- [ ] Changes UI
- [ ] Includes DB Migration (follow approval process in
[SIP-59](https://github.com/apache/superset/issues/13351))
- [ ] Migration is atomic, supports rollback & is backwards-compatible
- [ ] Confirm DB migration upgrade and downgrade tested
- [ ] Runtime estimates and downtime expectations provided
- [ ] Introduces new feature or API
- [ ] Removes existing feature or API
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]