Repository navigation
fix(dashboard): remove @has_access_api from filter state REST API - #43564
Conversation
Code Review Agent Run #28c683Actionable Suggestions - 0Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #43564 +/- ##
=======================================
Coverage 79.10% 79.11%
=======================================
Files 2878 2878
Lines 165634 165635 +1
Branches 38294 38296 +2
=======================================
+ Hits 131023 131035 +12
+ Misses 32123 32118 -5
+ Partials 2488 2482 -6
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Code Review Agent Run #062333Actionable Suggestions - 0Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
…for authenticated non-admin user
Code Review Agent Run #33562eActionable Suggestions - 0Additional Suggestions - 1
Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
…heck_access call in integration test
Code Review Agent Run #fe8d93Actionable Suggestions - 0Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
|
Thanks for the review @sadpandajoe! I've updated the tests in the latest commit:
|
…3564) Co-authored-by: FrancescoCastaldi <francesco.castaldi@mapsgroup.it>
SUMMARY
Fixes #43257
In
DashboardFilterStateRestApi,@has_access_apiand@apidecorators were erroneously present onpost()andput()endpoints. BecauseDashboardFilterStateRestApiinherits fromTemporaryCacheRestApi, endpoint access control and permissions are managed at the command level (verifying access to the underlying dashboard resource viaCheckAccessDataCommand).The presence of
@has_access_apicaused standard users and API clients to receive401 UnauthorizedonPOSTandPUTrequests when creating or updating filter state in dashboards, ascan_post/can_putpermissions forDashboardFilterStateRestApiare not registered in FAB's role manager.This PR removes
@has_access_apiand@apifrompost()andput(), aligning them withget()anddelete()in the same API as well asFormDataRestApi.BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
N/A (Backend REST API fix)
TESTING INSTRUCTIONS
POST /api/v1/dashboard/<pk>/filter_stateorPUT /api/v1/dashboard/<pk>/filter_state/<key>).ADDITIONAL INFORMATION
SUGGESTED LABELS
#bug:regression,api,api:dashboards,dashboard:native-filters,validation:validated,P2