Skip to content

fix(dashboard): remove @has_access_api from filter state REST API - #43564

Merged
rusackas merged 10 commits into
apache:masterfrom
FrancescoCastaldi:fix/filter-state-api-auth
Aug 29, 2026
Merged

rusackas merged 10 commits into
apache:masterfrom
FrancescoCastaldi:fix/filter-state-api-auth

Conversation

@FrancescoCastaldi

@FrancescoCastaldi FrancescoCastaldi commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

SUMMARY

Fixes #43257

In DashboardFilterStateRestApi, @has_access_api and @api decorators were erroneously present on post() and put() endpoints. Because DashboardFilterStateRestApi inherits from TemporaryCacheRestApi, endpoint access control and permissions are managed at the command level (verifying access to the underlying dashboard resource via CheckAccessDataCommand).

The presence of @has_access_api caused standard users and API clients to receive 401 Unauthorized on POST and PUT requests when creating or updating filter state in dashboards, as can_post / can_put permissions for DashboardFilterStateRestApi are not registered in FAB's role manager.

This PR removes @has_access_api and @api from post() and put(), aligning them with get() and delete() in the same API as well as FormDataRestApi.

BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF

N/A (Backend REST API fix)

TESTING INSTRUCTIONS

  1. Open a dashboard with native filters as an authenticated user.
  2. Apply or update a filter state (POST /api/v1/dashboard/<pk>/filter_state or PUT /api/v1/dashboard/<pk>/filter_state/<key>).
  3. Verify that the request succeeds (returns HTTP 200/201) without returning 401 Unauthorized.

ADDITIONAL INFORMATION

SUGGESTED LABELS

#bug:regression, api, api:dashboards, dashboard:native-filters, validation:validated, P2

@bito-code-review

bito-code-review Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #28c683

Actionable Suggestions - 0
Review Details
  • Files reviewed - 1 · Commit Range: 970e127..970e127
    • superset/dashboards/filter_state/api.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@github-actions github-actions Bot added the api Related to the REST API label Aug 26, 2026
@codecov

codecov Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.11%. Comparing base (a140e74) to head (38c5e7c).
⚠️ Report is 11 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master   #43564   +/-   ##
=======================================
  Coverage   79.10%   79.11%           
=======================================
  Files        2878     2878           
  Lines      165634   165635    +1     
  Branches    38294    38296    +2     
=======================================
+ Hits       131023   131035   +12     
+ Misses      32123    32118    -5     
+ Partials     2488     2482    -6     
Flag Coverage Δ
hive 37.95% <ø> (-0.01%) ⬇️
mysql 57.70% <ø> (-0.01%) ⬇️
postgres 57.73% <ø> (-0.01%) ⬇️
presto 39.86% <ø> (-0.01%) ⬇️
python 83.68% <ø> (+0.01%) ⬆️
sqlite 57.42% <ø> (-0.01%) ⬇️
unit 73.81% <ø> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@bito-code-review

bito-code-review Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #062333

Actionable Suggestions - 0
Review Details
  • Files reviewed - 2 · Commit Range: 970e127..3038c72
    • tests/integration_tests/dashboards/filter_state/api_tests.py
    • tests/unit_tests/dashboards/filter_state_api_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@pull-request-size pull-request-size Bot added size/L and removed size/M labels Aug 27, 2026
@pull-request-size pull-request-size Bot added size/M and removed size/L labels Aug 27, 2026
@pull-request-size pull-request-size Bot added size/L and removed size/M labels Aug 27, 2026
@bito-code-review

bito-code-review Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #33562e

Actionable Suggestions - 0
Additional Suggestions - 1
  • tests/integration_tests/dashboards/filter_state/api_tests.py - 1
    • Missed mock assertion · Line 273-273
      The test patches `create.check_access` (line 273) but never asserts it was called. The POST at line 286 triggers this mock, so add `mock_create_check_access.assert_called_once_with(dashboard_id)` after the POST status assertion to verify the create path's access check is exercised.
Review Details
  • Files reviewed - 1 · Commit Range: 3038c72..e38a9c5
    • tests/integration_tests/dashboards/filter_state/api_tests.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

Comment thread tests/unit_tests/dashboards/filter_state_api_test.py Outdated
@bito-code-review

bito-code-review Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #fe8d93

Actionable Suggestions - 0
Review Details
  • Files reviewed - 2 · Commit Range: e38a9c5..38c5e7c
    • tests/integration_tests/dashboards/filter_state/api_tests.py
    • tests/unit_tests/dashboards/filter_state_api_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@FrancescoCastaldi

Copy link
Copy Markdown
Contributor Author

Thanks for the review @sadpandajoe!

I've updated the tests in the latest commit:

  • Updated the unit tests ( ests/unit_tests/dashboards/filter_state_api_test.py) to explicitly assert that neither @has_access_api nor @api decorators are present on post() and put().
  • Added integration test assertions to verify that access control delegation to check_access works as expected for authenticated non-admin requests.

@rusackas
rusackas merged commit 058eaf7 into apache:master Aug 29, 2026
73 checks passed
rusackas pushed a commit that referenced this pull request Aug 29, 2026
…3564)

Co-authored-by: FrancescoCastaldi <francesco.castaldi@mapsgroup.it>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api Related to the REST API size/XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: @has_access_api on DashboardFilterStateRestApi causes 401 for all users (including admin) on POST/PUT

3 participants