Repository navigation
fix(auth): remove the legacy FAB password reset views and move password resets into the SPA - #44626
Conversation
Code Review Agent Run #6bb91dActionable Suggestions - 0Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
✅ Deploy Preview for superset-docs-preview ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
The flagged issue is correct. Exempting all To resolve this, you should narrow the exemption to only the specific endpoints required for the password change flow (e.g., |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #44626 +/- ##
==========================================
+ Coverage 81.65% 81.70% +0.05%
==========================================
Files 2977 2977
Lines 181262 181508 +246
Branches 41876 41936 +60
==========================================
+ Hits 148008 148303 +295
+ Misses 30526 30487 -39
+ Partials 2728 2718 -10
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Code Review Agent Run #5acea8Actionable Suggestions - 0Additional Suggestions - 2
Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
EnxDev
left a comment
There was a problem hiding this comment.
Went through this one and the logic holds up. The forced-change exemptions are tight, the flag clears in the same commit as the new hash, and the admin reset path hashes and invalidates sessions the way it should.
Two small notes inline: the Confirm Password asterisk in the create form, and an integration assertion that passes without the launcher patch.
EnxDev
left a comment
There was a problem hiding this comment.
Follow-up to my earlier pass on 779f810.
Both notes are handled in 517affe. required={!isEditMode} brings the asterisk back on Confirm Password in the create form without touching the validator. The integration loop that passed on the permission redirect is gone, and test_disable_legacy_password_reset_launchers really does check the hidden buttons and the NotFound, so the docstring pointing there holds up.
Nothing new from me, LGTM once CI finishes.
Code Review Agent Run #37e415Actionable Suggestions - 0Additional Suggestions - 1
Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
517affe to
41e24c3
Compare
Code Review Agent Run #a4f814Actionable Suggestions - 0Additional Suggestions - 11
Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
EnxDev
left a comment
There was a problem hiding this comment.
Follow-up to my earlier pass on 517affe.
Range-diffed the rebase: the three code commits are unchanged, and the only real difference is the messages.pot commit, which now carries all eight new modal msgids and matches every t() string in the two modals. Master's drift over the base doesn't touch any of these code paths, and CI is green.
One optional wording nit inline on UPDATING.md. Still LGTM.
| # exempt target can be resolved at all, return an error response rather | ||
| # than redirect, so a flagged user can never get stuck looping. | ||
| candidates = ["ResetMyPasswordView.this_form_get"] | ||
| candidates = [_PROFILE_PAGE_ENDPOINT] |
There was a problem hiding this comment.
A flagged user is unconditionally redirected to UserInfoView.list, which itself requires can_read on user — but the old redirect target, ResetMyPasswordView, was reachable by every authenticated user regardless of role (it was in ACCESSIBLE_PERMS). A custom role that lacks can_read on user (for example one that was only ever granted the legacy reset permissions) now gets redirected here, denied by FAB's own access check, and falls back only to logout — with no way left to reach a password-change flow and clear password_must_change. Is that intentional, or should the profile page (or some reachable change-password path) stay available to any authenticated user the way self-service reset used to be?
|
|
||
| pvms = self._get_all_pvms() | ||
| pvms = [ | ||
| pvm for pvm in self._get_all_pvms() if not self._is_legacy_password_pvm(pvm) |
There was a problem hiding this comment.
This filter only feeds set_role calls for Admin, Alpha, Gamma, sql_lab, and optionally Public — sync_role_definitions never rebuilds a custom (operator-defined) role. A custom role that already held ResetPasswordView/ResetMyPasswordView/UserDBModelView resetpasswords/resetmypassword permissions before upgrading keeps them after superset init, even though UPDATING.md and the new integration test claim/verify only that Admin/Alpha/Gamma no longer hold them. Should custom roles be swept for these stale permissions too, or is the UPDATING.md wording meant to be narrower than "no role"?
Code Review Agent Run #fcd016Actionable Suggestions - 0Review Details
Bito Usage GuideCommands Type the following command in the pull request comment and save the comment.
Refer to the documentation for additional commands. Configuration This repository uses Documentation & Help |
…gacy-fab-password-views # Conflicts: # superset/translations/messages.pot
Co-Authored-By: Evan Rusackas <evan@preset.io> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Dang, I just merged this and noticed there were open questions. Block if you wanna block, I guess ;) I'll dig in and open up a follow-up PR if warranted. |
|
Bito Automatic Review Skipped – PR Already Merged |
…tale legacy password perms from all roles Follow-up to #44626. UserInfoView.list requires can_read on user, which sync_role_definitions only grants to the built-in Admin/Alpha/Gamma roles. A user on a custom role lacking it who is forced to change their password got redirected into an infinite loop (profile page -> denied -> login -> already authenticated -> index -> profile page...) with no way out. The hook now checks reachability first and falls back to logout with an explanatory message instead. Separately, sync_role_definitions's legacy-password-pvm exclusion only ever touches the four built-in roles it resyncs; a custom role that already held ResetPasswordView/ResetMyPasswordView/UserDBModelView's resetpasswords/resetmypassword permissions before upgrading kept them indefinitely, contradicting UPDATING.md's "no role" claim. Added a data migration sweeping those stale, now fully inert permissions off every role, and narrowed the UPDATING.md wording to match. Co-Authored-By: Evan Rusackas <evan@preset.io> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…tale legacy password perms from all roles Follow-up to #44626. UserInfoView.list requires can_read on user, which sync_role_definitions only grants to the built-in Admin/Alpha/Gamma roles. A user on a custom role lacking it who is forced to change their password got redirected into an infinite loop (profile page -> denied -> login -> already authenticated -> index -> profile page...) with no way out. The hook now checks reachability first and falls back to logout with an explanatory message instead. Separately, sync_role_definitions's legacy-password-pvm exclusion only ever touches the four built-in roles it resyncs; a custom role that already held ResetPasswordView/ResetMyPasswordView/UserDBModelView's resetpasswords/resetmypassword permissions before upgrading kept them indefinitely, contradicting UPDATING.md's "no role" claim. Added a data migration sweeping those stale, now fully inert permissions off every role, and narrowed the UPDATING.md wording to match. Co-Authored-By: Evan Rusackas <evan@preset.io> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…tale legacy password perms from all roles Follow-up to #44626. UserInfoView.list requires can_read on user, which sync_role_definitions only grants to the built-in Admin/Alpha/Gamma roles. A user on a custom role lacking it who is forced to change their password got redirected into an infinite loop (profile page -> denied -> login -> already authenticated -> index -> profile page...) with no way out. The hook now checks reachability first and falls back to logout with an explanatory message instead. Separately, sync_role_definitions's legacy-password-pvm exclusion only ever touches the four built-in roles it resyncs; a custom role that already held ResetPasswordView/ResetMyPasswordView/UserDBModelView's resetpasswords/resetmypassword permissions before upgrading kept them indefinitely, contradicting UPDATING.md's "no role" claim. Added a data migration sweeping those stale, now fully inert permissions off every role, and narrowed the UPDATING.md wording to match. Co-Authored-By: Evan Rusackas <evan@preset.io> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* fix(echarts): fix sparse sub-daily bar sizing and x-axis mislabeling (apache#44628) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(mysql): require TLS when SSL is requested (apache#44723) * fix(dynamodb): render time bounds as ISO 8601 so sub-day ranges match stored timestamps (apache#44702) * fix(opensearch): page drill-to-detail samples with the OpenSearch SQL response format (apache#44703) * fix(gsheets): pass the OAuth2 token and delegation subject through connect_args (apache#44709) * fix(databricks): stop the string-type patch writing SQLAlchemy's shared colspecs (apache#44707) * fix(oracle): map Oracle NUMBER, BINARY_FLOAT/DOUBLE and CLOB column types (apache#44685) Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com> * chore(deps): bump undici from 7.29.0 to 7.30.0 in /superset-frontend in the security group across 1 directory (apache#44809) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com> * chore(deps): bump react-window from 2.3.2 to 2.3.3 in /superset-frontend (apache#44820) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(datafusion): render temporal SQL that DataFusion accepts (apache#44700) * fix(db2): set current_schema to the catalog name of the selected schema (apache#44706) * chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /superset-frontend/cypress-base (apache#44813) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * perf(security): memoise the user subject lookup within a request (apache#44017) Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746) * fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718) * chore(deps): bump the security group across 1 directory with 2 updates (apache#44824) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792) * chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697) Signed-off-by: hainenber <dotronghai96@gmail.com> * chore(deps): bump the security group across 1 directory with 2 updates (apache#44831) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: avoid provider calls when rendering datasource access denials (apache#44432) * fix(csv-import): add primary key when MySQL requires one (apache#44411) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(mcp): align histogram and waterfall query contracts (apache#44744) * ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(core): stop discarding API errors that quote an HTML tag (apache#42489) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395) * fix(sql): reject client-side file-transfer statements in query execution (apache#44496) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(sqllab): preserve exact decimals in results and exports (apache#44739) * fix(exasol): classify common server errors (apache#44721) * fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713) * fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708) * fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705) * fix(gsheets): align service-account validation and serialize upload dates (apache#44695) * fix(mcp): prioritize exact tool names in BM25 search (apache#44682) * test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(auth): drain flash messages on the login page (apache#44605) * fix(gantt): prevent y-axis category labels from being clipped (apache#44321) * fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626) Co-authored-by: jayvenn21 <jvennamreddy@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * fix: increase dataset edit modal size (apache#38215) (apache#39257) Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com> Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(doris): offer the connection form by matching the installed driver (apache#44736) * chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore: drop cypress-matrix-required from required status checks (apache#44854) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(e2e): remove Cypress infrastructure (apache#44829) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(oauth2): refresh a token rejected when a connection opens (apache#44765) * feat(table): add multi-level column header groups (apache#43938) Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mcp): enforce tool deadlines without blocking the server (apache#44581) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(playwright): select existing dashboards without creating duplicates (apache#44856) * feat(mcp): support tab-scoped dashboard layouts (apache#44797) * fix: size 'Drill to detail' table header correctly (apache#44807) * fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786) * fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618) Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * fix(frontend): use html2canvas for chart image export on Safari (apache#44529) * chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(home): redirect users without an ID before rendering (apache#44456) * chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800) * fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * ci: require babel-extract to pass before merging master (apache#44543) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(mcp): report a chart's live dataset id and name (apache#44681) * fix(retention): skip models without purge policies before scanning (apache#44874) * fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396) * fix(semantic-layer): require explicit member identity reselection (apache#44370) * fix(logging): register LogRestApi only once (apache#44732) * chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232) Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> * fix(users): stop update_me setting self-referential changed_by_fk (apache#44866) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722) Signed-off-by: hainenber <dotronghai96@gmail.com> * fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * docs(databases): add ClickHouse Managed Postgres (apache#44870) Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com> * test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(change-detector): classify changed files by language, not directory (apache#44895) * chore(mcp): fix malformed tool and prompt docstrings (apache#44572) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): cover viz switch and control dependency logic (apache#44842) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): add fetchTopNValues unit tests (apache#44841) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): add saveModalReducer unit tests (apache#44839) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): add datasourcesReducer unit tests (apache#44840) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(frontend): await the userEvent calls that needed restructuring (apache#44799) * fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463) * fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213) * fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix: downgrade deprecated query_object field warnings to info (apache#43520) * docs: remove stale Selenium references after Playwright-only switch (apache#44243) * fix(mcp): include feature_availability in instance://metadata resource (apache#44891) * fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366) Co-authored-by: Superset Dev <dev@superset.apache.org> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(ci): add Chromatic visual regression testing for Storybook (apache#44103) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796) * test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sec): sanitize HTML text before shown as impact item's label (apache#43825) * fix(chart): accept quarter and day in end-of time ranges (apache#43204) * fix(sql-lab): avoid duplicate generated result column names (apache#44189) * fix(chart): sort Heatmap Y-axis by default when unset (apache#44588) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357) * fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574) Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> * fix(mcp): stop partial-update tools from advertising null defaults (apache#44573) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * fix(cartodiagram): share Pie colors across locations in Explore (apache#44794) * fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787) * fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828) * fix(import): remove duplicate config redefinition in load_configs (apache#44932) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * perf(deletion-retention): one window pass for repeat predicate (apache#44349) * chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump holidays from 0.104 to 0.105 (apache#44936) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(mcp): preserve calling constraints in compact tool discovery (apache#44656) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(oracle): cover cancel-query against a real running statement (apache#44908) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960) * fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * docs(mcp): document semantic-layer MCP tools (apache#44130) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805) Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com> * chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977) * chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973) * chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245) * fix(explore): preserve pending column configuration edits (apache#44931) * fix(mcp): return actionable authorized column suggestions (apache#44603) * chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(build): remove unused `polyline` Python dep (apache#44961) * fix: full CSV download in AgGrid (apache#41696) Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(mcp): support filter_range and filter_timegrain filters (apache#44893) * fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(mcp): avoid duplicate SQL execution results (apache#44949) * fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mcp): allow bounding dashboard dataset columns (apache#44951) * feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948) * fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666) * fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612) * feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699) * fix(embedded): refuse guest row-level security on semantic views (apache#44987) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(ag-grid-table): expand JSON values in table cells (apache#44907) Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> * chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362) Co-authored-by: Claude Code <noreply@anthropic.com> * feat(bignumber): add an alignment control (apache#44554) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775) Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dashboard,explore): wire addWarningToast into download callers (apache#44154) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat: add global async query playwright tests (apache#43004) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(table): omit dormant grains from semantic aggregate requests (apache#44455) * fix(semantic-layers): offer valid table ordering choices (apache#44806) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815) Co-authored-by: Evan Rusackas <evan@preset.io> * fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773) * feat(mcp): allow default values on filter_select native filters (apache#44985) * feat(mcp): add structured dashboard text component management (apache#44560) * fix(explore): avoid mutating ZoomConfigControl configs (apache#44957) Co-authored-by: Cursor <cursoragent@cursor.com> * test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947) * fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933) * chore(deps): bump the security group across 1 directory with 9 updates (apache#45026) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the security group across 1 directory with 6 updates (apache#45025) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021) * fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(semantic): add optional metadata refresh SDK contract (apache#44834) Signed-off-by: Mike Bridge <michael.bridge@preset.io> * fix(semantic): map layer views as a collection (apache#44902) * feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892) * fix(semantic): reject SQL clauses on semantic views (apache#44899) * fix(security): bind contextual access checks to the datasource type and id (apache#45002) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the storybook group in /docs with 2 updates (apache#45046) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(post-processing): stop duplicating columns in _append_columns (apache#45018) * feat(plugin-chart-echarts): add a value axis label control (apache#43660) * fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(pivot-table): collapse row groups by default (apache#45030) * fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925) * fix(semantic): hide and ignore series limits that have no series columns (apache#44909) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(async): show the real error for a failed async chart query (apache#45054) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(semantic-layer): show provider queries from chart results (apache#44206) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * perf(security): batch dashboard fallback datasource resolution (apache#44993) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(versioning): preserve history across savepoint rollback (apache#45033) * fix(cache): evict rejected cached GET requests (apache#45055) * fix(semantic): return a client error for unsupported time grains (apache#45053) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs: add DouroECI logo and contributor to In the Wild (apache#45096) Co-authored-by: José Henrique <jose.teixeira@douroeci.com> * fix(charts): clear perms of charts whose datasource no longer exists (apache#44926) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * feat: SIP-209 Improved Alerts & Reports (apache#44992) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(ci): configure more grouped dep upgrades across npm subprojects (apache#44696) Signed-off-by: hainenber <dotronghai96@gmail.com> * fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963) * fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962) Co-authored-by: Joe Li <joe@preset.io> * fix(explore): honor a controlled ControlPopover open prop (apache#44959) * fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(explore): dispatch datasource metadata fetch (apache#44958) * fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832) * fix(dashboard): refresh semantic metadata across edits (apache#45052) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * chore: Update CODEOWNERS to include @sadpandajoe (apache#45120) * feat(mcp): add typed Sunburst chart support (apache#43771) * fix(semantic-layer): require write access for configuration schema enrichment (apache#45107) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091) * chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134) --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: hainenber <dotronghai96@gmail.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Mike Bridge <michael.bridge@preset.io> Co-authored-by: Joe Li <joe@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com> Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com> Co-authored-by: shaurya <shauryajaiswal.dev@gmail.com> Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com> Co-authored-by: Mike Bridge <michael.bridge@preset.io> Co-authored-by: Elizabeth Thompson <eschutho@gmail.com> Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com> Co-authored-by: Gaston Laterza <glaterza@gmail.com> Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com> Co-authored-by: chadek <32199566+chadek@users.noreply.github.com> Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com> Co-authored-by: jayvenn21 <jvennamreddy@gmail.com> Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com> Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com> Co-authored-by: SBIN2010 <Sbin2010@mail.ru> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: mattmc3 <mattmc3@gmail.com> Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com> Co-authored-by: Greg Neighbors <gkneighb@mac.com> Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan> Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com> Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz> Co-authored-by: Archita-kale <kalearchita22@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com> Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> Co-authored-by: Younes Beriane <paranoyouz@gmail.com> Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com> Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com> Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com> Co-authored-by: Sam Firke <sfirke@users.noreply.github.com> Co-authored-by: Superset Dev <dev@superset.apache.org> Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com> Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in> Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com> Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn> Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com> Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com> Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com> Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com> Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com> Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com> Co-authored-by: Beto Dealmeida <roberto@dealmeida.net> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com> Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com> Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com> Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de> Co-authored-by: drivaspreset <diego.rivas@preset.io> Co-authored-by: Abhinav <alpha9coder@gmail.com> Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com> Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com> Co-authored-by: Divyansh Yadav <anshmcs@gmail.com> Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com> Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com> Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com> Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com> Co-authored-by: José Henrique <jose.teixeira@douroeci.com> Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com> Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com> Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746) * fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718) * chore(deps): bump the security group across 1 directory with 2 updates (apache#44824) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792) * chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697) Signed-off-by: hainenber <dotronghai96@gmail.com> * chore(deps): bump the security group across 1 directory with 2 updates (apache#44831) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: avoid provider calls when rendering datasource access denials (apache#44432) * fix(csv-import): add primary key when MySQL requires one (apache#44411) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(mcp): align histogram and waterfall query contracts (apache#44744) * ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(core): stop discarding API errors that quote an HTML tag (apache#42489) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395) * fix(sql): reject client-side file-transfer statements in query execution (apache#44496) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(sqllab): preserve exact decimals in results and exports (apache#44739) * fix(exasol): classify common server errors (apache#44721) * fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713) * fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708) * fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705) * fix(gsheets): align service-account validation and serialize upload dates (apache#44695) * fix(mcp): prioritize exact tool names in BM25 search (apache#44682) * test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(auth): drain flash messages on the login page (apache#44605) * fix(gantt): prevent y-axis category labels from being clipped (apache#44321) * fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626) Co-authored-by: jayvenn21 <jvennamreddy@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * fix: increase dataset edit modal size (apache#38215) (apache#39257) Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com> Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(doris): offer the connection form by matching the installed driver (apache#44736) * chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore: drop cypress-matrix-required from required status checks (apache#44854) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(e2e): remove Cypress infrastructure (apache#44829) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(oauth2): refresh a token rejected when a connection opens (apache#44765) * feat(table): add multi-level column header groups (apache#43938) Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mcp): enforce tool deadlines without blocking the server (apache#44581) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(playwright): select existing dashboards without creating duplicates (apache#44856) * feat(mcp): support tab-scoped dashboard layouts (apache#44797) * fix: size 'Drill to detail' table header correctly (apache#44807) * fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786) * fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618) Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * fix(frontend): use html2canvas for chart image export on Safari (apache#44529) * chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(home): redirect users without an ID before rendering (apache#44456) * chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800) * fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * ci: require babel-extract to pass before merging master (apache#44543) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(mcp): report a chart's live dataset id and name (apache#44681) * fix(retention): skip models without purge policies before scanning (apache#44874) * fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396) * fix(semantic-layer): require explicit member identity reselection (apache#44370) * fix(logging): register LogRestApi only once (apache#44732) * chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232) Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> * fix(users): stop update_me setting self-referential changed_by_fk (apache#44866) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722) Signed-off-by: hainenber <dotronghai96@gmail.com> * fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * docs(databases): add ClickHouse Managed Postgres (apache#44870) Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com> * test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(change-detector): classify changed files by language, not directory (apache#44895) * chore(mcp): fix malformed tool and prompt docstrings (apache#44572) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): cover viz switch and control dependency logic (apache#44842) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(explore): add fetchTopNValues unit tests (apache#44841) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): add saveModalReducer unit tests (apache#44839) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): add datasourcesReducer unit tests (apache#44840) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(frontend): await the userEvent calls that needed restructuring (apache#44799) * fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463) * fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213) * fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix: downgrade deprecated query_object field warnings to info (apache#43520) * docs: remove stale Selenium references after Playwright-only switch (apache#44243) * fix(mcp): include feature_availability in instance://metadata resource (apache#44891) * fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366) Co-authored-by: Superset Dev <dev@superset.apache.org> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(ci): add Chromatic visual regression testing for Storybook (apache#44103) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796) * test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sec): sanitize HTML text before shown as impact item's label (apache#43825) * fix(chart): accept quarter and day in end-of time ranges (apache#43204) * fix(sql-lab): avoid duplicate generated result column names (apache#44189) * fix(chart): sort Heatmap Y-axis by default when unset (apache#44588) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> * fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357) * fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574) Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> * fix(mcp): stop partial-update tools from advertising null defaults (apache#44573) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * fix(cartodiagram): share Pie colors across locations in Explore (apache#44794) * fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787) * fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828) * fix(import): remove duplicate config redefinition in load_configs (apache#44932) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * perf(deletion-retention): one window pass for repeat predicate (apache#44349) * chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump holidays from 0.104 to 0.105 (apache#44936) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(mcp): preserve calling constraints in compact tool discovery (apache#44656) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(oracle): cover cancel-query against a real running statement (apache#44908) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960) * fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * docs(mcp): document semantic-layer MCP tools (apache#44130) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805) Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com> * chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977) * chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973) * chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245) * fix(explore): preserve pending column configuration edits (apache#44931) * fix(mcp): return actionable authorized column suggestions (apache#44603) * chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(build): remove unused `polyline` Python dep (apache#44961) * fix: full CSV download in AgGrid (apache#41696) Co-authored-by: rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(mcp): support filter_range and filter_timegrain filters (apache#44893) * fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(mcp): avoid duplicate SQL execution results (apache#44949) * fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mcp): allow bounding dashboard dataset columns (apache#44951) * feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948) * fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666) * fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612) * feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699) * fix(embedded): refuse guest row-level security on semantic views (apache#44987) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(ag-grid-table): expand JSON values in table cells (apache#44907) Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> * chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022) Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362) Co-authored-by: Claude Code <noreply@anthropic.com> * feat(bignumber): add an alignment control (apache#44554) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775) Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * fix(dashboard,explore): wire addWarningToast into download callers (apache#44154) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat: add global async query playwright tests (apache#43004) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(table): omit dormant grains from semantic aggregate requests (apache#44455) * fix(semantic-layers): offer valid table ordering choices (apache#44806) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815) Co-authored-by: Evan Rusackas <evan@preset.io> * fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773) * feat(mcp): allow default values on filter_select native filters (apache#44985) * feat(mcp): add structured dashboard text component management (apache#44560) * fix(explore): avoid mutating ZoomConfigControl configs (apache#44957) Co-authored-by: Cursor <cursoragent@cursor.com> * test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947) * fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933) * chore(deps): bump the security group across 1 directory with 9 updates (apache#45026) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the security group across 1 directory with 6 updates (apache#45025) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021) * fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(semantic): add optional metadata refresh SDK contract (apache#44834) Signed-off-by: Mike Bridge <michael.bridge@preset.io> * fix(semantic): map layer views as a collection (apache#44902) * feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892) * fix(semantic): reject SQL clauses on semantic views (apache#44899) * fix(security): bind contextual access checks to the datasource type and id (apache#45002) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the storybook group in /docs with 2 updates (apache#45046) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(post-processing): stop duplicating columns in _append_columns (apache#45018) * feat(plugin-chart-echarts): add a value axis label control (apache#43660) * fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056) Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> * feat(pivot-table): collapse row groups by default (apache#45030) * fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925) * fix(semantic): hide and ignore series limits that have no series columns (apache#44909) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(async): show the real error for a failed async chart query (apache#45054) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(semantic-layer): show provider queries from chart results (apache#44206) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * perf(security): batch dashboard fallback datasource resolution (apache#44993) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(versioning): preserve history across savepoint rollback (apache#45033) * fix(cache): evict rejected cached GET requests (apache#45055) * fix(semantic): return a client error for unsupported time grains (apache#45053) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs: add DouroECI logo and contributor to In the Wild (apache#45096) Co-authored-by: José Henrique <jose.teixeira@douroeci.com> * fix(charts): clear perms of charts whose datasource no longer exists (apache#44926) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093) Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * feat: SIP-209 Improved Alerts & Reports (apache#44992) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(ci): configure more grouped dep upgrades across npm subprojects (apache#44696) Signed-off-by: hainenber <dotronghai96@gmail.com> * fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963) * fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962) Co-authored-by: Joe Li <joe@preset.io> * fix(explore): honor a controlled ControlPopover open prop (apache#44959) * fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(explore): dispatch datasource metadata fetch (apache#44958) * fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832) * fix(dashboard): refresh semantic metadata across edits (apache#45052) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * chore: Update CODEOWNERS to include @sadpandajoe (apache#45120) * feat(mcp): add typed Sunburst chart support (apache#43771) * fix(semantic-layer): require write access for configuration schema enrichment (apache#45107) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> * fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091) * chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134) * fix(semantic-layer): honor provider preferred time dimension (apache#44997) Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> * feat(dashboard): add column allowlist to Group By native filter (apache#43736) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * fix(soft-delete): preserve a shared datasource permission on purge (apache#45034) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * perf(versioning): defer capture policy until versioned work (apache#44928) * fix(date-parser): reject malformed time ranges instead of scanning everything (apache#45098) * chore(deps-dev): bump wait-on from 9.4.0 to 9.5.1 in /superset-frontend (apache#45048) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(deps): bump mapbox-gl from 3.31.0 to 3.32.0 in /superset-frontend (apache#45049) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Joe Li <joe@preset.io> * chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-embedded-sdk (apache#45074) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the swc group across 2 directories with 1 update (apache#45118) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump @types/node in /superset-embedded-sdk (apache#45121) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump swagger-ui-react from 5.33.0 to 5.33.1 in /docs (apache#45122) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump yargs from 18.1.0 to 18.2.0 in /superset-frontend (apache#45129) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump oxfmt in /docs (apache#45119) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: hainenber <dotronghai96@gmail.com> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Mike Bridge <michael.bridge@preset.io> Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com> Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com> Co-authored-by: Mike Bridge <michael.bridge@preset.io> Co-authored-by: Joe Li <joe@preset.io> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Evan Rusackas <evan@preset.io> Co-authored-by: Elizabeth Thompson <eschutho@gmail.com> Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com> Co-authored-by: Gaston Laterza <glaterza@gmail.com> Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com> Co-authored-by: chadek <32199566+chadek@users.noreply.github.com> Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com> Co-authored-by: jayvenn21 <jvennamreddy@gmail.com> Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com> Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com> Co-authored-by: SBIN2010 <Sbin2010@mail.ru> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com> Co-authored-by: mattmc3 <mattmc3@gmail.com> Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com> Co-authored-by: Greg Neighbors <gkneighb@mac.com> Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan> Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com> Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz> Co-authored-by: Archita-kale <kalearchita22@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com> Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com> Co-authored-by: Younes Beriane <paranoyouz@gmail.com> Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com> Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com> Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com> Co-authored-by: Sam Firke <sfirke@users.noreply.github.com> Co-authored-by: Superset Dev <dev@superset.apache.org> Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com> Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in> Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com> Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn> Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com> Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com> Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com> Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com> Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com> Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com> Co-authored-by: Beto Dealmeida <roberto@dealmeida.net> Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io> Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com> Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com> Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com> Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de> Co-authored-by: drivaspreset <diego.rivas@preset.io> Co-authored-by: Abhinav <alpha9coder@gmail.com> Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com> Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com> Co-authored-by: Divyansh Yadav <anshmcs@gmail.com> Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com> Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com> Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com> Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com> Co-authored-by: José Henrique <jose.teixeira@douroeci.com> Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com> Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com> Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
…(partial backport of #44626) On 7.0, PUT /api/v1/me/ requires current_password whenever a password is set (#42934), but the SPA "Reset my password" modal never sends it, so self-service password changes always fail with 400 -- a regression from 6.1. This backports only the self-service part of #44626 (d2fb52a): - the modal gains a "Current password" field and sends it when filled; - CurrentUserPutSchema no longer requires current_password at schema level; CurrentUserRestApi.pre_update already requires and verifies it for every account that has a stored password, while one without (e.g. provisioned by an external auth backend) can set its first password; - a successful self-service change clears a pending forced password change; clear_password_must_change no longer commits on its own, so it rides the /me unit of work, and reset_password commits after it. Not backported: removing the legacy FAB ResetPassword/ResetMyPassword views and their permissions, redirecting forced changes to the SPA, and the admin user modal rework.
SUMMARY
Fixes #37700. Supersedes #37773 by @jayvenn21, whose
add_view_no_menuregistration intercept, launcher hiding and tests this builds on (credited as co-author on the commit).The Flask-AppBuilder server-rendered password reset pages (
/resetpassword/form,/resetmypassword/form) survived the SPA migration and were still reachable in 6.0. #37773 gated them behind a newENABLE_LEGACY_FAB_PASSWORD_VIEWSflag. Looking at what people actually asked for, it was the SPA inputs, not a switch to keep the old pages around, so this drops the flag idea and removes the views outright, and makes sure the SPA covers every job they had:PUT /api/v1/security/users/<id>. That endpoint iscan_put on User(admin) and never required a current password, which is the right rule for an admin resetting someone else's account. The self-servicePUT /api/v1/me/requirescurrent_passwordwhenever the account already has a stored password; an account without one (external auth, first-time setup) sets its first password without it.current_passwordwhen filled in (the field is optional in the modal, the API decides whether it is needed). It didn't send it before, so since fix(security): harden account password-change and session-invalidation handling #42934 made the field mandatory the SPA modal was actually broken against its own API.ENABLE_FORCE_PASSWORD_CHANGE) used to redirect toResetMyPasswordView. It now lands on/user_info/, with the profile page and only the endpoints it calls (GET/PUT /api/v1/me/and the CSRF token) exempt from the hook so the page is usable; the rest of those APIs (guest_tokenincluded) stays behind the gate, so a flagged user can still only reach that page and log out. A successful self-service change through/api/v1/me/now clearspassword_must_change(previously only the FAB view did), in the same unit of work as the new hash.Backend: the two views are never registered (FAB adds them unconditionally for
AUTH_DB, and a blueprint can't be removed once added, soregister_views()interceptsadd_view_no_menufor the duration of FAB's registration), the "Reset Password" / "Reset my password" launchers on the FAB user pages are hidden and answer 404 instead ofBuildError, andsync_role_definitionsstops assigning the staleResetPasswordView/ResetMyPasswordView/ launcher permissions that upgraded installs still carry in their metadata DB.ENABLE_LEGACY_FAB_PASSWORD_VIEWSdoes not exist.BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
Before:
/resetpassword/form?pk=<id>and/resetmypassword/formrender the FAB forms; the Users list edit modal has no password fields; the profile "Reset my password" modal fails with "This field is required to change the password."After: both routes 404. The Users list edit modal shows "New password" and "Confirm new password" under Groups (blank keeps the current password, mismatch is rejected client-side). The profile "Reset my password" modal shows "Current password" (optional, needed only when the account already has one), "New password" and "Confirm Password".
TESTING INSTRUCTIONS
/user_info/), "Reset my password", enter the current and a new password; confirm the new one works and the old one doesn't.ENABLE_FORCE_PASSWORD_CHANGE = True, flag a user (set_password_must_change(user_id)), log in as them: every page redirects to/user_info/, the reset modal there works, and after changing the password the redirect stops. Logging out is possible throughout./resetpassword/form?pk=1and/resetmypassword/formreturn 404;superset initleaves no role withResetPasswordView,ResetMyPasswordView,resetpasswordsorresetmypasswordpermissions.Locally: security + users unit tests (418 passed), the touched integration tests in
core_tests.py(2 passed) and the 5 touched jest suites (27 passed).users/api_tests.pyandsession_invalidation_tests.pyhave 8 failures here that reproduce identically onmaster(this machine's test config makes Public role like Gamma and has no Redis), so CI is the arbiter for those.ADDITIONAL INFORMATION
Breaking change: the two legacy routes and their permissions are gone (UPDATING.md entry included). Deployments that deep-link to them should point at
/user_info/or the Users list.🤖 Generated with Claude Code