Elizabeth Thompson
1cadf39ce8
test(sql): cover SqlglotError fallback branch in parse_predicate
...
The regression test only exercised the ParseError branch, leaving the
generic sqlglot.errors.SqlglotError fallback in
SQLStatement.parse_predicate uncovered and dropping line coverage below
the 100% gate. Add a test that mocks sqlglot.parse_one to raise a bare
SqlglotError and asserts it is converted to a SupersetParseError.
2026-08-28 22:14:52 +00:00
Elizabeth Thompson
876b8641e2
fix(sql): catch sqlglot ParseError when parsing RLS predicates
...
SQLStatement.parse_predicate called sqlglot.parse_one unguarded, so a
syntactically invalid RLS predicate raised a raw sqlglot ParseError.
Reachable via apply_rls (e.g. POST /api/v1/sqllab/estimate with
RLS_IN_SQLLAB enabled), this surfaced as an opaque 500 instead of a
typed 422.
Wrap the call to convert ParseError/SqlglotError into SupersetParseError,
mirroring the existing idiom in SQLStatement._parse.
2026-08-28 16:49:17 +00:00
62d74be0af
fix(metadb): apply SUPERSET_META_DB_LIMIT after join instead of per-table ( #36304 ) ( #42598 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
Co-authored-by: Joe Li <joe@preset.io >
2026-08-25 19:31:11 -07:00
04017f3956
fix(sqllab): re-validate access against rendered SQL and tighten cache/permalink scoping ( #43394 )
...
Co-authored-by: Superset Dev <dev@superset.apache.org >
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com >
2026-08-21 12:35:06 -07:00
1e65d93a83
fix(sql): handle ORDER BY in embedded MSSQL queries ( #43127 )
...
Co-authored-by: Bexultan Mustafin <bexultan.mustafin@ffins.kz >
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com >
2026-08-14 14:07:10 -04:00
a63483b9b1
fix(sql): rebase Dremio dialect on sqlglot's native dialect ( #43099 )
...
Co-authored-by: Superset Dev <dev@superset.apache.org >
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com >
Co-authored-by: Joe Li <joe@preset.io >
2026-08-13 13:16:06 -07:00
ʈᵃᵢ
b8ca729f9f
fix(sql): only force a LIMIT onto query expressions ( #43097 )
2026-08-13 10:43:45 -07:00
Evan Rusackas and Claude Code
ed696b9933
test(sql): pin optimizer hint blocks survive format() round-trip ( #38189 ) ( #42733 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-08-12 14:49:55 -07:00
onheap and keyao_yang
a501fed560
fix(rls): handle same-named CTEs and quoted aliases in the SQL rewrite ( #43005 )
...
Co-authored-by: keyao_yang <keyao.yang@airbnb.com >
2026-08-12 10:38:36 -03:00
Evan Rusackas and Claude Code
b4f3fae288
fix(sql): guard FORCE_LIMIT against SHOW statements ( #36939 ) ( #42588 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-08-11 23:33:15 -07:00
Evan Rusackas and Claude Opus 4.8
584466e02b
fix(sql-lab): improved SQL statement parsing and validation ( #42928 )
...
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-11 19:35:43 -07:00
Shaitan and Claude Opus 4.8
b6504eb111
fix(sql): resolve schema/catalog-qualified table references in CTE detection ( #42717 )
...
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-10 12:28:31 -07:00
Evan Rusackas and Claude Code
2f9bde5579
fix(sql): preserve quoted-identifier casing for the HANA dialect ( #39328 ) ( #42731 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-08-04 20:39:35 -07:00
bcf0361a91
feat(KustoKQL): Add support for NULL / IS NOT NULL operator ( #37890 )
...
Co-authored-by: ag-ramachandran <ramacg@microsoft.com >
Co-authored-by: Joe Li <joe@preset.io >
2026-07-23 18:28:37 -07:00
Damian Pendrak
1392fbc9b2
fix(sql): validate Custom SQL metric has an aggregate under GROUP BY ( #42199 )
2026-07-22 09:28:57 +02:00
Evan Rusackas and Claude Sonnet 5
666b6805c4
test(sql): prove Oracle GROUP BY stays explicit for virtual-dataset charts ( #42255 )
...
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com >
2026-07-21 09:59:34 -07:00
b3757870cc
fix(sqllab): apply SQL_QUERY_MUTATOR in SQL Lab when MUTATE_AFTER_SPLIT is set ( #41127 )
...
Co-authored-by: Lucas Wolkersdorfer <lucas.wolkersdorfer@rise-world.com >
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com >
2026-07-20 15:36:45 -07:00
Evan Rusackas and Claude Code
7b0969131f
test(sql): prove ClickHouse parametric aggregates parse cleanly ( #37285 ) ( #41836 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-07-07 08:53:49 -07:00
Evan Rusackas and Claude Code
de5a31a2cf
test(sql): prove Oracle GROUP BY is no longer rewritten to ordinals ( #35414 ) ( #41834 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-07-07 08:53:05 -07:00
Evan Rusackas and Claude Code
2aa43f6f0f
fix(sql): stop sanitize_clause from rewriting user SQL semantics ( #36113 ) ( #41125 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-07-06 18:03:26 -07:00
Shaitan and Claude Opus 4.8
2da2db6c7c
feat(sql): schema-qualified table denylist + information_schema/lo_* defaults ( #41120 )
...
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-01 16:57:45 +01:00
3651020014
fix(sql): cap parser input length via SQL_MAX_PARSE_LENGTH config ( #40499 )
...
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com >
Co-authored-by: sha174n <pedro.sousa@preset.io >
Co-authored-by: Evan Rusackas <evan@preset.io >
2026-07-01 16:32:12 +01:00
215b207ae4
fix(sql): detect set operations and nested selects in subquery check ( #38452 )
...
Co-authored-by: sha174n <pedro.sousa@preset.io >
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-22 20:27:32 -07:00
Jean Dupuis
b2e5f80db2
fix(sql): preserve multi-arg DISTINCT in sanitize_clause and format ( #39340 )
2026-06-19 13:02:50 -07:00
6a1091d576
fix(sql): broaden mutating-statement detection in SQL Lab parser ( #40421 )
...
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com >
Co-authored-by: sha174n <pedro.sousa@preset.io >
2026-06-16 15:07:34 -07:00
b85a2cdab1
fix: ODPS (MaxCompute) data source table preview failed ( #38174 )
...
Co-authored-by: zhutong6688 <zhutong66@163.com >
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com >
2026-06-05 17:57:44 -07:00
Shaitan and Claude Opus 4.7
56fd991efd
fix(dataset): unify validation for stored and adhoc SQL expressions ( #40392 )
...
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com >
2026-06-03 12:55:50 +01:00
Shaitan and Claude Sonnet 4.6
f7f50a7977
fix(sqllab): quote CTAS target identifiers and validate tmp_table_name format ( #40245 )
...
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-03 12:55:25 +01:00
Shaitan and Claude Opus 4.7
6eaee211aa
fix(sqllab): require dataset match for raw query access ( #40409 )
...
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com >
2026-06-02 21:50:27 +01:00
Evan Rusackas and Claude Code
b97d3ef520
fix(api,sql): use json_response in Api.query and log dialect fallback ( #40644 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-06-02 11:48:46 -07:00
Evan Rusackas and Claude Sonnet 4.6
1632b235ae
fix(sqllab): surface stacktrace in SQL Lab error responses ( #28248 ) ( #40585 )
...
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-02 10:41:39 -07:00
Evan Rusackas and Claude Code
c39a47cbac
test(sql-parser): pin WITH+UNION as non-mutating across dialects ( #25659 ) ( #40138 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-05-20 10:08:21 -07:00
Alexandru Soare
b98bd2a07a
fix(mcp): Block destructive DDL (DROP, TRUNCATE, ALTER) in execute_sql ( #39621 )
2026-05-20 14:29:15 +03:00
Evan Rusackas and Claude Code
b5ad4a7a07
test(sql-parser): pin TimescaleDB hyperfunctions parse on postgresql ( #32028 ) ( #40142 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-05-19 19:53:33 -07:00
Evan Rusackas and Claude Code
9bfa0642a1
test(sql-parser): pin quoted identifiers with spaces are not subqueries ( #32541 , #32684 ) ( #40143 )
...
Co-authored-by: Claude Code <noreply@anthropic.com >
2026-05-18 14:21:59 -07:00
Igor Khrol and Joe Li
3363b48180
fix(spark): register Spark SQLAlchemy dialect so spark:// URIs resolve to SparkEngineSpec ( #38299 )
...
Co-authored-by: Joe Li <joe@preset.io >
2026-05-12 12:33:17 -04:00
Beto Dealmeida
4311a15eb2
feat(sqlglot): Vertica dialect ( #39969 )
2026-05-08 14:34:34 -03:00
Vitor Avila
ad5e3170dd
fix: OpenSearch dialect identifier delimiters ( #39953 )
2026-05-07 16:19:27 -03:00
Alexandru Soare
adfbbf1433
fix(sql): quote identifiers in transpile_to_dialect to fix case-sensitive column filters ( #39521 )
2026-05-06 10:53:09 +03:00
Vitor Avila
5af17c7976
fix(OpenSearch): OpenSearch dialect for sqlglot ( #39538 )
2026-04-22 12:17:15 -03:00
Luiz Otavio
0b419a07f5
fix: add comments to SQL clause validation ( #39167 )
2026-04-16 09:19:39 -03:00
Amin Ghadersohi
68067d7f44
fix(mcp): handle OAuth-authenticated databases in execute_sql ( #39166 )
2026-04-09 15:47:00 -04:00
Alexandru Soare
6465450b64
fix(firebolt): Firebolt SQL entered with EXCLUDE is rewritten to EXCEPT ( #38742 )
2026-03-19 10:21:50 -07:00
Beto Dealmeida
a854fa60a2
feat: apply RLS conservatively ( #38683 )
2026-03-17 10:20:09 -04:00
Michael S. Molina
357e35dc62
refactor(core): reorganize superset-core packages into feature-based structure ( #38448 )
2026-03-05 17:41:15 -03:00
Michael S. Molina
c41942a38a
chore(deps): Upgrade sqlglot from 27.15.2 to 28.10.0 ( #37841 )
2026-02-10 13:13:11 -03:00
Amin Ghadersohi
15b3c96f8e
fix(security): Add table blocklist and fix MCP SQL validation bypass ( #37411 )
2026-02-09 14:12:06 +01:00
87bbd54d0a
feat(examples): Transpile virtual dataset SQL on import ( #37311 )
...
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com >
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net >
Co-authored-by: bito-code-review[bot] <188872107+bito-code-review[bot]@users.noreply.github.com>
2026-01-22 09:50:05 -08:00
ankitajhanwar2001
d8f7ae83ee
fix(sqlglot): use Athena dialect for awsathena parsing ( #36747 )
2026-01-12 10:06:46 -08:00
Michael S. Molina and Copilot
28e3ba749e
feat: SQL execution API for Superset ( #36529 )
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-12-16 14:39:29 -03:00