sadpandajoe commented on code in PR #45060:
URL: https://github.com/apache/superset/pull/45060#discussion_r4235847181


##########
superset/common/query_context_factory.py:
##########
@@ -27,23 +27,40 @@
 from superset.daos.chart import ChartDAO
 from superset.daos.datasource import DatasourceDAO
 from superset.explorables.base import Explorable
+from superset.extensions import security_manager
 from superset.models.slice import Slice
+from superset.security.manager import SupersetSecurityManager
 from superset.superset_typing import Column
 from superset.utils.core import DatasourceDict, DatasourceType, is_adhoc_column
 
 if TYPE_CHECKING:
     from superset.connectors.sqla.models import BaseDatasource
 
 
+def _uses_stock_raise_for_access() -> bool:
+    """Whether the security manager keeps the stock ``raise_for_access``.
+
+    The semantic preflight passes an empty ``queries`` list, which only the
+    stock check is known not to read. ``__class__`` resolves through the
+    security manager proxy to the configured manager's class.
+    """
+    return (
+        security_manager.__class__.raise_for_access

Review Comment:
   This detects an override by comparing the class attribute, so a security 
manager that inherits the stock method but wraps it on the instance 
(`self.raise_for_access = ...` in `__init__`), or a `superset_config.py` that 
reassigns `SupersetSecurityManager.raise_for_access` to a wrapper, still counts 
as stock. The wrapper then runs in the preflight with `queries=[]`, and one 
that reads `query_context.queries[0]` for metric or column checks raises 
`IndexError` (500) on a semantic-view request that returned 200 before this 
change. Could this compare the resolved bound method on the proxied manager (or 
the instance `__dict__`) instead, so those cases skip the preflight like a 
subclass override does?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to