Compare commits

..
Author SHA1 Message Date
sadpandajoeandClaude Sonnet 5 7f362a84b8 fix(explore): stop dashboard permalink key from leaking into chart URL
RESERVED_CHART_URL_PARAMS was missing permalink_key while the analogous
RESERVED_DASHBOARD_URL_PARAMS already excluded it. This asymmetry let a
dashboard permalink's permalink_key, merged into a chart's form_data via
a shared cache keyed only by sliceId, get copied into the chart's own
Explore URL when opened from a dashboard. On refresh, Explore forwarded
that dashboard-salted key to the explore permalink resolver, which fails
key decoding against the wrong salt and falls back to a stub datasource,
producing the "missing datasource" error.

Add permalink_key to RESERVED_CHART_URL_PARAMS, mirroring the pattern
already used correctly on the dashboard side and in FilterBar's
EXCLUDED_URL_PARAMS. As an accepted side effect, this also makes
Explore's own permalink key (/explore/p/<key>/) drop out of the URL
after refresh instead of staying sticky, matching FilterBar's existing
behavior for dashboards.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-20 05:06:22 +00:00
Grégoire GaillyandEvan Rusackas c2d653b4b8 fix: set maxHeight of List components to height when in AutoSizer (#43056)
Co-authored-by: Evan Rusackas <evan@preset.io>
2026-08-19 16:56:30 -07:00
Đỗ Trọng HảiandJoe Li 5a96c3f538 chore(ci): disable Git commit info capture in Playwright E2E tests to avoid timeout (#43213)
Signed-off-by: hainenber <dotronghai96@gmail.com>
Co-authored-by: Joe Li <joe@preset.io>
2026-08-19 16:54:44 -07:00
ʈᵃᵢ faf7c34c0a fix(explore): legacy boolean filters and limit available operators based on calculated column type (#43341) 2026-08-19 15:37:09 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> b8fca2145d chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.0 (#43322)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 14:40:02 -07:00
Alejandro Solares c10054f521 fix(plugin-chart-chord): declare react as a peerDependency (#43304) 2026-08-19 17:35:38 -04:00
Amin GhadersohiandClaude 8c500ccee1 fix(users): show password validation errors (#43191)
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-19 16:57:46 -04:00
Joe LiandClaude Sonnet 5 6d77efad29 fix(chart): stop contextmenu propagation in BigNumberViz (#43267)
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-19 13:57:28 -07:00
Amin GhadersohiandClaude 8222db3340 fix(dataset): preserve legacy default dashboard URLs (#43190)
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-19 14:44:54 -04:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 01ce8358a6 chore(deps-dev): bump globals from 17.9.0 to 17.10.0 in /superset-websocket (#43321)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:48 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 53a8a0e140 chore(deps): bump the docusaurus-openapi group in /docs with 2 updates (#43323)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:44 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> eafbff9f8d chore(deps-dev): bump globals from 17.9.0 to 17.10.0 in /docs (#43324)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:37 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 1339bcd9da chore(deps): bump swagger-ui-react from 5.32.12 to 5.32.13 in /docs (#43325)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:34 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 334e280489 chore(deps): bump dompurify from 3.4.12 to 3.4.13 in /superset-frontend (#43326)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:30 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> c07f3ebf2d chore(deps-dev): bump @swc/plugin-emotion from 14.15.0 to 14.19.0 in /superset-frontend (#43328)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 11:36:26 -07:00
Sumit KumarandClaude Opus 4.8 1569915096 feat(multi-value): array-typed column filters with two-tier operators (ClickHouse MVP) (#41279)
Signed-off-by: thedeceptio <thedeceptio@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-19 10:56:49 -07:00
BexultanandBexultan Mustafin fde0ba26d1 fix(mcp): validate virtual dataset metadata and surface errors (#43129)
Co-authored-by: Bexultan Mustafin <bexultan.mustafin@ffins.kz>
2026-08-19 10:50:37 -07:00
DanielSwift1992 097c99b19c fix: remove a labeler glob that matches no files (#43270) 2026-08-18 16:21:01 -07:00
David Dallakyan 5ce52e531d fix(clickhouse): add PT1S time grain (#43217) 2026-08-18 15:49:18 -07:00
34cd50cc48 test(chart): mock the event log endpoint in the drill-to-detail menu test (#43183)
Co-authored-by: bikashJMV <bikash@jmv.co.in>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Joe Li <joe@preset.io>
2026-08-18 13:51:54 -07:00
c0ab5f3385 fix(dashboard): preserve native filter keys for dataset-less filters on save (#42898)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
2026-08-18 21:30:50 +03:00
ʈᵃᵢ 7d4f30574f feat(tooltip): add Truncate labels control to timeseries charts (#43272) 2026-08-18 11:05:07 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> e4ea6e23d8 chore(deps): bump supercluster from 8.0.1 to 9.0.0 in /superset-frontend (#43290)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 10:35:17 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> a13a5f1af4 chore(deps-dev): bump @typescript-eslint/eslint-plugin from 8.65.0 to 8.67.0 in /superset-websocket (#43284)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 10:34:39 -07:00
Endi Monan f994602096 fix(dashboard): align list OpenAPI schema (#43256) 2026-08-18 10:22:50 -07:00
Amin GhadersohiandClaude Fable 5 086b4af65d feat(mcp): per-resource token scopes with user-permission intersection (#42297)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 13:11:27 -04:00
fd063d17bf fix(security): harden account password-change and session-invalidation handling (#42934)
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Joe Li <joe@preset.io>
2026-08-18 17:40:08 +01:00
60e1802c52 fix(dashboard): mute the Group By display control loading spinner (#42879)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
2026-08-18 09:37:43 -07:00
Joe LiandClaude Opus 4.8 2d1daac11a fix(explore): samples endpoint now honors requested row limit (#43148)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-18 09:28:04 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 3c90bdc6f0 chore(deps-dev): bump oxfmt from 0.62.0 to 0.63.0 in /superset-frontend (#43293)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 06:15:08 -07:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>rusackasClaude Opus 4.8
ebab31adc2 chore(deps): bump antd from 6.5.4 to 6.6.0 in /superset-frontend (#43294)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-18 06:15:04 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 936f073b9a chore(deps-dev): bump @typescript-eslint/parser from 8.66.0 to 8.67.0 in /superset-websocket (#43281)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:46 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> d12320239a chore(deps-dev): bump typescript-eslint from 8.66.0 to 8.67.0 in /superset-websocket (#43282)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:42 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 8ef7be5788 chore(deps-dev): bump oxfmt from 0.62.0 to 0.63.0 in /superset-websocket (#43283)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:39 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 72458ab26f chore(deps-dev): bump @typescript-eslint/eslint-plugin from 8.66.0 to 8.67.0 in /superset-frontend in the typescript-eslint group (#43285)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:33 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 5105f13726 chore(deps-dev): bump the typescript-eslint group in /docs with 3 updates (#43286)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:29 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> bdafb6c330 chore(deps-dev): bump oxfmt from 0.62.0 to 0.63.0 in /docs (#43287)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:25 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> b4d79462ec chore(deps-dev): bump oxlint from 1.77.0 to 1.78.0 in /superset-frontend (#43288)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:21 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 49374f1fe5 chore(deps): bump antd from 6.5.4 to 6.6.0 in /docs (#43289)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:00:17 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> f766de6d0d chore(deps): bump dompurify from 3.4.12 to 3.4.13 in /superset-frontend (#43291)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 02:59:59 -07:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> ed20e729d0 chore(deps): bump google-auth-library from 11.0.0 to 11.0.1 in /superset-frontend (#43292)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 02:59:55 -07:00
13eb47a1da fix(api): improved request handling and embedded dashboard scoping (#42930)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
2026-08-17 23:50:25 -07:00
Elizabeth ThompsonandClaude Opus 4.8 98136d547c fix(reports): fail closed on alert screenshot capture instead of delivering a blank (#43031)
Signed-off-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-18 00:03:15 -04:00
Elizabeth ThompsonandClaude Opus 4.8 e2070d79dc fix(reports): wait for ECharts paint before capturing report screenshots (#43077)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-18 00:02:36 -04:00
148 changed files with 6836 additions and 1562 deletions
+1 -1
View File
@@ -29,7 +29,7 @@
"dependencies:python":
- changed-files:
- any-glob-to-any-file:
- 'superset/requirements/**'
- 'requirements/**'
- 'superset/translations/requirements.txt'
- 'RELEASING/requirements.txt'
+1 -1
View File
@@ -48,7 +48,7 @@ jobs:
python-version: "3.11"
- name: Install uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
uses: astral-sh/setup-uv@ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d # v10.0.0
with:
python-version: "3.11"
enable-cache: true
+3
View File
@@ -24,6 +24,8 @@ assists people when migrating to a new version.
## Next
- `SAMPLES_ROW_LIMIT` is now the default for `/datasource/samples` requests without a valid explicit `per_page`, rather than a hard per-request ceiling; explicit limits are honored up to the existing global row-limit ceiling, matching `/chart/data` SAMPLES requests.
### OAuth2 database callback metrics include their outcome
The unqualified `DatabaseRestApi.oauth2` StatsD counter has been replaced with
@@ -31,6 +33,7 @@ The unqualified `DatabaseRestApi.oauth2` StatsD counter has been replaced with
`DatabaseRestApi.oauth2.error`. Update monitoring rules and dashboards that consume
the old counter to use the outcome-specific replacements.
- [42930](https://github.com/apache/superset/pull/42930): Dataset import data-URI fetches no longer honor an HTTP(S) proxy when `DATASET_IMPORT_ALLOW_INTERNAL_DATA_URLS` is `False` (the default): the connection is now made directly to the destination so the peer-address check validates the real target instead of a proxy's. Deployments that require an egress proxy to reach legitimate external data URLs for dataset import should set `DATASET_IMPORT_ALLOW_INTERNAL_DATA_URLS = True` or otherwise ensure those URLs resolve without one.
- [42935](https://github.com/apache/superset/pull/42935): The MCP service now refuses to start (`MCPAuthConfigError`) when `MCP_JWT_ISSUER` trusts more than one issuer and no `MCP_USER_RESOLVER` is configured, instead of only logging a warning. This was already a documented misconfiguration (the default resolver isn't issuer-scoped, so distinct trusted issuers minting the same username/email would resolve to the same Superset user); deployments trusting multiple issuers must configure an `MCP_USER_RESOLVER` that derives its identity from the token's `iss` claim before upgrading. Single-issuer deployments are unaffected.
- [42393](https://github.com/apache/superset/pull/42393): Exported dataset YAML now carries a `uuid` for each metric and column so that custom folder assignments (which reference metrics/columns by UUID) survive an import into another workspace. This affects any export bundle that contains datasets, not just a dataset export: chart, dashboard, database and full-asset exports all embed the same dataset YAML, so a dashboard exported from this release also fails to import into an older one even though no dataset was exported directly. As with `folders` and `currency_code_column`, the affected `datasets/` files fail schema validation (`Unknown field: uuid`) when imported into Superset releases that predate this change; regenerate or hand-edit exports for older targets in mixed-version fleets.
- [42300](https://github.com/apache/superset/pull/42300): Timeseries charts (line/area/bar) with a Y-axis bound in effect — either an explicit `yAxisBounds` or one derived from `truncateYAxis` — now clamp out-of-range data points to that bound instead of letting ECharts drop the point (and the line segments around it) entirely. Any existing chart with a configured Y-axis bound and data outside it will look different after upgrading: a gap becomes a point pinned to the boundary. The clamp also rewrites the value ECharts reads for that point's tooltip and data label, so the displayed value is the bound rather than the true observation.
+13 -1
View File
@@ -400,7 +400,7 @@ Once enabled, each user manages their own keys from their profile page:
1. Open the user menu (top-right) and click **Info** to navigate to the User Info page
2. Expand the **API Keys** section
3. Click **+ API Key**
4. Enter a name and (optionally) an expiration date
4. Enter a name and optionally select resource scopes
5. Copy the generated token — it is shown only once
Only users with the `can_read` and `can_write` permissions on `ApiKey` (granted by default to Admins) can manage API keys.
@@ -415,6 +415,18 @@ Authorization: Bearer <your-api-key>
This works for all REST API endpoints and the MCP server. The request is executed with the permissions of the user who created the key.
#### API Key Scopes
The creation dialog can restrict an API key to MCP resource actions such as
`superset:dashboard:read` or `superset:chart:write`. A scope is an additional
restriction: it never grants a permission that the creating user does not
already have through Superset RBAC. Write scopes also cover update and delete
operations for that resource; `superset:sqllab:write` covers SQL execution.
Keys created without scopes retain legacy RBAC-only behavior. The scoped-key
restrictions described here are enforced by the MCP server; regular REST API
routes continue to apply their existing Superset RBAC checks.
#### Use Cases
- **CI/CD pipelines** — automated chart/dashboard exports and imports
+9 -9
View File
@@ -61,11 +61,11 @@
"@storybook/addon-docs": "^10.5.7",
"@superset-ui/core": "^0.20.4",
"@swc/core": "^1.15.47",
"antd": "^6.5.4",
"antd": "^6.6.0",
"baseline-browser-mapping": "^2.11.13",
"caniuse-lite": "^1.0.30001809",
"docusaurus-plugin-openapi-docs": "^5.1.3",
"docusaurus-theme-openapi-docs": "^5.1.3",
"docusaurus-plugin-openapi-docs": "^5.2.0",
"docusaurus-theme-openapi-docs": "^5.2.0",
"js-yaml": "^5.2.3",
"json-bigint": "^1.0.0",
"prism-react-renderer": "^2.4.1",
@@ -78,7 +78,7 @@
"remark-import-partial": "^0.0.2",
"reselect": "^5.2.0",
"storybook": "^10.5.7",
"swagger-ui-react": "^5.32.12",
"swagger-ui-react": "^5.32.13",
"swc-loader": "^0.2.7",
"tinycolor2": "^1.4.2",
"unist-util-visit": "^5.1.0"
@@ -89,14 +89,14 @@
"@eslint/js": "^9.39.2",
"@types/js-yaml": "^4.0.9",
"@types/react": "^19.1.8",
"@typescript-eslint/eslint-plugin": "^8.66.0",
"@typescript-eslint/parser": "^8.66.0",
"@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.67.0",
"eslint": "^9.39.2",
"eslint-plugin-react": "^7.37.5",
"globals": "^17.9.0",
"oxfmt": "^0.62.0",
"globals": "^17.10.0",
"oxfmt": "^0.63.0",
"typescript": "~6.0.3",
"typescript-eslint": "^8.66.0",
"typescript-eslint": "^8.67.0",
"webpack": "^5.109.2"
},
"browserslist": {
+44 -32
View File
@@ -3407,22 +3407,26 @@
"nullable": true,
"type": "string"
},
"description": {
"nullable": true,
"type": "string"
},
"editors": {
"items": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.Subject"
},
"type": "array"
},
"id": {
"type": "integer"
},
"is_managed_externally": {
"type": "boolean"
},
"owners": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.User2"
},
"published": {
"nullable": true,
"type": "boolean"
},
"roles": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.Role"
},
"slug": {
"maxLength": 255,
"nullable": true,
@@ -3432,10 +3436,10 @@
"readOnly": true
},
"tags": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.Tag"
},
"thumbnail_url": {
"readOnly": true
"items": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.Tag"
},
"type": "array"
},
"url": {
"readOnly": true
@@ -3444,21 +3448,46 @@
"format": "uuid",
"nullable": true,
"type": "string"
},
"viewers": {
"items": {
"$ref": "#/components/schemas/DashboardRestApi.get_list.Subject1"
},
"type": "array"
}
},
"type": "object"
},
"DashboardRestApi.get_list.Role": {
"DashboardRestApi.get_list.Subject": {
"properties": {
"id": {
"type": "integer"
},
"name": {
"maxLength": 64,
"label": {
"maxLength": 255,
"type": "string"
},
"type": {
"type": "integer"
}
},
"required": ["name"],
"required": ["label", "type"],
"type": "object"
},
"DashboardRestApi.get_list.Subject1": {
"properties": {
"id": {
"type": "integer"
},
"label": {
"maxLength": 255,
"type": "string"
},
"type": {
"type": "integer"
}
},
"required": ["label", "type"],
"type": "object"
},
"DashboardRestApi.get_list.Tag": {
@@ -3511,23 +3540,6 @@
"required": ["first_name", "last_name"],
"type": "object"
},
"DashboardRestApi.get_list.User2": {
"properties": {
"first_name": {
"maxLength": 64,
"type": "string"
},
"id": {
"type": "integer"
},
"last_name": {
"maxLength": 64,
"type": "string"
}
},
"required": ["first_name", "last_name"],
"type": "object"
},
"DashboardRestApi.post": {
"properties": {
"certification_details": {
@@ -16506,7 +16518,7 @@
},
"result": {
"items": {
"type": "object"
"$ref": "#/components/schemas/DashboardRestApi.get_list"
},
"type": "array"
}
+277 -259
View File
@@ -1142,6 +1142,11 @@
resolved "https://registry.yarnpkg.com/@babel/runtime/-/runtime-7.29.7.tgz#12022450c45a4da6d8d8287b18a4ff2ddb23f768"
integrity sha512-Nq8OhGWiZIZGV6hLHoyAKLLcJihP/xFeBMGJoUrxTX2psI8dCifzLhZISFb+VWS3wFMRDmCGw5R+dOySCqPLhw==
"@babel/runtime@^8.0.0":
version "8.0.0"
resolved "https://registry.yarnpkg.com/@babel/runtime/-/runtime-8.0.0.tgz#d7bd513e6843662346552c2798ab895716cf97f2"
integrity sha512-sL6cvO2IfkSu/iU+zs2S/w01B7A8V7suXSIKEN4hPFFdZoiPGxrj5pAG0lCaqLWiEIrjKzdznIWuaLcxPR53qw==
"@babel/template@^7.29.7":
version "7.29.7"
resolved "https://registry.yarnpkg.com/@babel/template/-/template-7.29.7.tgz#4d9d4004f645cdd304de958c725162784ecac700"
@@ -3170,100 +3175,100 @@
resolved "https://registry.yarnpkg.com/@oxc-resolver/binding-win32-x64-msvc/-/binding-win32-x64-msvc-11.23.0.tgz#8b66dbfa7b796139e719063fc0e44084e80a1c15"
integrity sha512-gUGJpr+Rn6zMxm5juApV0K3U845i8t47o8k+rbO0BHbi4PoJIfSPeQmrE2dgohQm2g5k6iviNFyXCGqvmaYUpw==
"@oxfmt/binding-android-arm-eabi@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-android-arm-eabi/-/binding-android-arm-eabi-0.62.0.tgz#3f5b9d3ba944f42ad3fa2697b9fef88a8c9d4ce0"
integrity sha512-pdsv0C4gPjJ8H1+sd8u0BDx+yLACTL+rgeMIOL1ln4ihSnhw8CWXtYWgvcSkyTfgGBIzFKab+d8rx9Xl4en/Kw==
"@oxfmt/binding-android-arm-eabi@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-android-arm-eabi/-/binding-android-arm-eabi-0.63.0.tgz#136176dc94fdc41e21415cc770d86f5066282e0f"
integrity sha512-YmRth4ZPGgEXcgmkhvANbC9uD67dxmSobW7DQuyt5tOBOKvPnIpk5SVHBj88E+7wMNRI2FhqaDbOhQFBix+b8A==
"@oxfmt/binding-android-arm64@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-android-arm64/-/binding-android-arm64-0.62.0.tgz#4c7e2c567f645ed051be100318e9e3f716630c1b"
integrity sha512-WC3YQ7uS/KtDrjmqwBviwFKe9qeoi+eXx8aX1z/ffG23Md75myjrJaQqTuJvdOLPoa4EYTjDWH0dHXfwulCVog==
"@oxfmt/binding-android-arm64@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-android-arm64/-/binding-android-arm64-0.63.0.tgz#10bc42457179210061c801122a64304619e3bdab"
integrity sha512-icbahX8X2X3sRamOMecvdYeZXWjPDazRDIfvWfy7Ca1nc/ZDT2Y9k5Nt7s46EqFd7NQPdgk+CM3/SgIT5LPCaQ==
"@oxfmt/binding-darwin-arm64@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-darwin-arm64/-/binding-darwin-arm64-0.62.0.tgz#6c8007ae65ed17f9d1ecc6c680da19ec19276c67"
integrity sha512-GM8Yf3LjjaR1I8PD0SfeoIlwhsh9GvSF+cQ8sf624Yxnjsyumn95aFzYfKJVefblfDIiOAnZ7QVm2sa21Er/0Q==
"@oxfmt/binding-darwin-arm64@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-darwin-arm64/-/binding-darwin-arm64-0.63.0.tgz#5f9084d9a760a1836387f8970a7f9d614ec3d909"
integrity sha512-WV+Ze5v5gI2qoj8jpAovt8KBTW8pjEz/AiMXXjeTQS+Bmf/MmZXTS40S8xNPDszX+W8WDv2Bbk6qKrMTtUGu1A==
"@oxfmt/binding-darwin-x64@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-darwin-x64/-/binding-darwin-x64-0.62.0.tgz#0661a0274e8625921c5a054aeb21a36251946e6b"
integrity sha512-d5THp7F8bCxLqNogEXDORRsQD6dosf3EyFtnXfBer6v+8tGdcWIjoDX9WaXrrF/26zOmL8qHpPTKCEvpBDmZkQ==
"@oxfmt/binding-darwin-x64@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-darwin-x64/-/binding-darwin-x64-0.63.0.tgz#badd4a02218a9a62319817d5c337b30159a54a21"
integrity sha512-CJGSBdDxXOWIpoFXHpverimCvz084KA7L483rqJ44c3jDtzv6d4qOSoR/V9ywSHfV+Ks1lwIj2P49BFhunLNAA==
"@oxfmt/binding-freebsd-x64@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-freebsd-x64/-/binding-freebsd-x64-0.62.0.tgz#f3345001102ac3e6c2947920d6d1676e9cf97e75"
integrity sha512-1DnrtXGZooOZ0fHgAXZUaDQzBVh1CM2MNW4oBXyQ2aWKvCHjyljvT9fgBkOM0fEOb96X5eqtcfJ0YUVt9jj66g==
"@oxfmt/binding-freebsd-x64@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-freebsd-x64/-/binding-freebsd-x64-0.63.0.tgz#a17261e95c8ebef1f76d8aaac746a64fdb6ba51e"
integrity sha512-BDfKY+KhL2078cgswBBFQPAYuxCy93bS/iC5frdSeSbTLcGrR6VC2hsuPTanoJmg84+wSyWl0wWC1eR+uTnkRg==
"@oxfmt/binding-linux-arm-gnueabihf@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-0.62.0.tgz#ddc03bc2a899f2071d6706c06dfdec3a7f3e8b5a"
integrity sha512-4pQDHOYRH+Huqe0StIaWyvk2CVl/aTaqSrbZpA3/pLS2xH24ME7lBgYprhQF2fRkHBzhGGGKliwxFsDdHwx59g==
"@oxfmt/binding-linux-arm-gnueabihf@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-0.63.0.tgz#baeee34bb08e0769af878623f442e83bc0aacd7a"
integrity sha512-Ov1cQEXT4mj7cojAokWSS1eoxkoyvbDfAbxNsGIKY2o36kvdAaFzPxRN6NxFRk9fD72B8oCoTTX/NuYTUWlpsg==
"@oxfmt/binding-linux-arm-musleabihf@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm-musleabihf/-/binding-linux-arm-musleabihf-0.62.0.tgz#5e82208d612c4caf64ada75e129e34d1a9eefb2c"
integrity sha512-X0jAaZJFMCVKhB6YyWVTQ/wN2DLsBcZKSMqTS76bF6riT+XZdtg2FPEdjDvdVbunO9cG+tWiVaEs4Zs38lxYog==
"@oxfmt/binding-linux-arm-musleabihf@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm-musleabihf/-/binding-linux-arm-musleabihf-0.63.0.tgz#e70d5697ec4b6bb5f87a3f019e01b3f956b8e44b"
integrity sha512-0LE7ro3+6L79jcMANycAZfRaC7zxr9YZ2+vEL5uMD9QlEep+rS/r1kSJsnuLl991NXJZD60euh0PC1GHrR20vw==
"@oxfmt/binding-linux-arm64-gnu@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-0.62.0.tgz#eb379bc58aa962e753d58b4cc68ff4081bc19a5d"
integrity sha512-682Z8T5s8T5ATArYtsejKvbIfd8LEAXyyDkKkoZVq8HND7Vx8TYLlrDjDSeYfodMeVwHOgkj13lJYR8cj6vUSg==
"@oxfmt/binding-linux-arm64-gnu@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-0.63.0.tgz#638a8ed4f3d256c50aeb6d2c19cfc65792c902e1"
integrity sha512-izPk+2Z4gjuZK32Fqh5qXoMpT/2NXzLh++ob57HiEiVSQZ1iYXu8EKMzb+K5AvWyIEXhdDIt7ADjGGtFhkT9Bw==
"@oxfmt/binding-linux-arm64-musl@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm64-musl/-/binding-linux-arm64-musl-0.62.0.tgz#dc1c62510405e874bf6a53a34f548032eb6dfed7"
integrity sha512-lk25fAl7KWaLWVJcW0CHEXB7QlQZtx5eDkjpaGMK0hzXTjUe0Wmlu8IKuFHoviSOcEJedRTs4VE/506VqGxGew==
"@oxfmt/binding-linux-arm64-musl@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-arm64-musl/-/binding-linux-arm64-musl-0.63.0.tgz#af5a9b787f5233f27a3360ad56235fc1b011f760"
integrity sha512-alPmbOuWXFXiSo+lOtv6X71C7SYMEDW2WVvywOvf9BwKgEhSNGhMTLeFVSjKUMCamcjbbgVdsWF8GN1uy8xshg==
"@oxfmt/binding-linux-ppc64-gnu@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-0.62.0.tgz#9f9afee327090024db86b70ec81a57ad06bb2f00"
integrity sha512-SFyNqHQLwySceWNLhiSldx7wPXRAzP0L0WcW9GegP3uWrpZGJiZlQO85NbHAFPEfxR9PhZ9qSnZryEh7+v+4Gw==
"@oxfmt/binding-linux-ppc64-gnu@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-0.63.0.tgz#c1a211206134a5577e355a495989e0d733218d60"
integrity sha512-BdzCPvolJc4AWZ+YMzgUDJcDzbQWrFjYuqBHoNHNqP1aCaluQRJNs4k3vNU5IG7vTpjf9zeD73D7MFM1TecZpg==
"@oxfmt/binding-linux-riscv64-gnu@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-riscv64-gnu/-/binding-linux-riscv64-gnu-0.62.0.tgz#4427d42ee3bad0e55b38dc76fe14a7e5318c360c"
integrity sha512-KYj55C1ywJfHo6+aKDuEmUtVEdJALsC5GwayDGsI6FGz2GxFqNr/mA8nxVsNbJzm7sE5MRqTQ9ziImSzhYXysA==
"@oxfmt/binding-linux-riscv64-gnu@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-riscv64-gnu/-/binding-linux-riscv64-gnu-0.63.0.tgz#4863f0311e5c1b88f75ef822959b3ca4fd938937"
integrity sha512-7sIgfLzqtNKSkMGsGVyRpHwpjNezRg2XONvUOheFZs95TSZpM0JAuPpA8KrQFsWc4wPU95roX2O69JgH8igOgw==
"@oxfmt/binding-linux-riscv64-musl@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-riscv64-musl/-/binding-linux-riscv64-musl-0.62.0.tgz#a117f82909f075cf07c333842d89a5638429e21d"
integrity sha512-BhZDNo5GOU5nC378RhD0/XpvaEBHsH3HLgJp8YZX3A0InC7oivzA63HsRmiXFLtLSHAstEVrDf6fbC7Rs8Jh/A==
"@oxfmt/binding-linux-riscv64-musl@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-riscv64-musl/-/binding-linux-riscv64-musl-0.63.0.tgz#ad05a017d12553e2f544743c4940adb552aa1d1c"
integrity sha512-9Tcg0y0WcVa6Mm9AgcgFMseDS+VkFJZpKZ8We9SpDY4gg5jewSwln+0sO04QLcTS1BtfDl9MwR+NfID8L7PUTg==
"@oxfmt/binding-linux-s390x-gnu@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-0.62.0.tgz#3fac79fefe7ffc3f0a9393678ebd782aac918fcd"
integrity sha512-UyAFmyHkgSgUJ/wOM4p3U8AC2yAFvRH5PNBs7TnK0fObTT/XSWcdr/lAzPSWaekHaZFaMeFZyk9n93Joq3J93A==
"@oxfmt/binding-linux-s390x-gnu@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-0.63.0.tgz#2803f539db15bc66db115888fa8f84d6531ed2b9"
integrity sha512-qWKC1pEOpx1qYhXaugPhHUeXwSfqEOk2wJH2LqVXGPV5iQYfdAZdt+d2XDiX4DTSWA2QDMUcFB+wEORh3Xn/sA==
"@oxfmt/binding-linux-x64-gnu@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-x64-gnu/-/binding-linux-x64-gnu-0.62.0.tgz#8da207bef27941f0265c129d1c7c82c7cf91d1ce"
integrity sha512-1iYMP0leytWazFubD/WnINJuIrzRPuoL1aWEJdlGezEzDbTxcd29R4r8IUzP2oWeKst5V02uMJgR2NILlPlG6w==
"@oxfmt/binding-linux-x64-gnu@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-x64-gnu/-/binding-linux-x64-gnu-0.63.0.tgz#c22a06a60ae2d6b3de522095e0c50a816040a033"
integrity sha512-S9wXYOiGSqYGS4Fx/TFsY+xDd/7dE5s+rUgbA4TsHiVF9e8J3ZcKmP7dsP/7iqLI9Wz7Ic7TzEr3mdthRCTdrA==
"@oxfmt/binding-linux-x64-musl@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-x64-musl/-/binding-linux-x64-musl-0.62.0.tgz#e55cf9b7c8c2204fdbb5d4818f8c5ba02aa49360"
integrity sha512-4rA/URtJSTVNVAQz6Q8wf7SaRvOXVy+TizriT9hs/Y1XhLR/R+92uWKRQG8yFWRAIEBbFHJ6WevQcl/G9SXEfw==
"@oxfmt/binding-linux-x64-musl@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-linux-x64-musl/-/binding-linux-x64-musl-0.63.0.tgz#48d3eeaf8e3757f638cf92de5ee4858befc9c0a3"
integrity sha512-5eGyTJuMZNwBSHCivXt8Yuta6GeTYksOPXRk2MIhajiyFGQx7bjaHIwY+ZusAoFHhT157A9x6sktLjYo9D5oMQ==
"@oxfmt/binding-openharmony-arm64@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-openharmony-arm64/-/binding-openharmony-arm64-0.62.0.tgz#4998769ee1b5894efcd6cb99729d5a75f4c09dd1"
integrity sha512-mSZuFHU2ar1KLUjXpI2QBQcJ1VsOB3mOCgQXuXCpKs19dgh4u+OaovNfrWDfiJb+ihJ2+f7YFcaO9bS2dlTCXA==
"@oxfmt/binding-openharmony-arm64@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-openharmony-arm64/-/binding-openharmony-arm64-0.63.0.tgz#02be9e140ae35ba30f52bdce27612fece4a01ab3"
integrity sha512-Rz7hx+Dv3DoW/S6pwVAyjfFXp7/trdQ1zg+vNmsdsdDNlUccugp4XNqambSuEAeP0DaG9k72AtNyfDXCEg0AGw==
"@oxfmt/binding-win32-arm64-msvc@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-0.62.0.tgz#e09eaabdde76c885c4f8a190518c2eb2de08548a"
integrity sha512-OfwuhkcjDlqC4EgDojtiV9mzpLqeB9KqTOWPOjLEYBVdDCVSxqW3qzp/xcIxsbtI0UgGCnKvAqYKyY25kf5JZw==
"@oxfmt/binding-win32-arm64-msvc@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-0.63.0.tgz#2226eaf52b6345a2cb926499216b2486cf0dbec2"
integrity sha512-T/IuizKN9mr4Xw6YYnptkXRNdLkyIlUZ7c8zfTOBpoytZyJ1BAsMUvsMDEx0X4YvSMpaivm+DR8112rQfzC25g==
"@oxfmt/binding-win32-ia32-msvc@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-ia32-msvc/-/binding-win32-ia32-msvc-0.62.0.tgz#f36e306308923977365270d8b26290f4ca2fcfa5"
integrity sha512-P9uDDNFRzghO3X8QAzhkjKhK7JvtABsVn8UYtFX7uor12IAnwNt8nNIctvfWj1JkQU/kE+fmLRPiw7XlrIHsZw==
"@oxfmt/binding-win32-ia32-msvc@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-ia32-msvc/-/binding-win32-ia32-msvc-0.63.0.tgz#58d263bb5ecd7330c02f9dcd8cda10f66e42e74b"
integrity sha512-XjrO5FJ5Wl9vsAxtCP1G/eaeT6y1K2s9CICUHGE42cEjou32/J6S+B1KnrOAboj6E7uhJnwPbRSvznWcxNdA0g==
"@oxfmt/binding-win32-x64-msvc@0.62.0":
version "0.62.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-x64-msvc/-/binding-win32-x64-msvc-0.62.0.tgz#bb6545e581d5ee7111084dbabeec7fe548bae418"
integrity sha512-dlI5SY7XYQCiCBafntWagCR6HcAJB/NpsLtdlPx8x08+Osz8Ok1HHz1GZuusegCe/VoJ6pAnF5a4pd5OZAq7qQ==
"@oxfmt/binding-win32-x64-msvc@0.63.0":
version "0.63.0"
resolved "https://registry.yarnpkg.com/@oxfmt/binding-win32-x64-msvc/-/binding-win32-x64-msvc-0.63.0.tgz#02a166c8a8049c55d0096d1ba9d8e73f3a4d26a7"
integrity sha512-sgsHCQy432OTQH4Ikk3tZptp3GqwnhwUDuY0loBH41zyHWfMZY9v8Dy78wsnSofHejvFozZGgJgBB1A0LQRwMQ==
"@parcel/watcher-android-arm64@2.5.6":
version "2.5.6"
@@ -3532,13 +3537,13 @@
dependencies:
"@babel/runtime" "^7.24.4"
"@rc-component/cascader@~1.17.0":
version "1.17.0"
resolved "https://registry.yarnpkg.com/@rc-component/cascader/-/cascader-1.17.0.tgz#52c0eceada2c7b4b37ebe822c19a6544b9562edf"
integrity sha512-3cVNG0zrQF1PoXq262L3wGCU+/YLEC1mGSVHDl577dQmA0ZKkXFbY6nwyXo+beCcM7buo49t24jkr+QZdL7O8w==
"@rc-component/cascader@~1.22.0":
version "1.22.0"
resolved "https://registry.yarnpkg.com/@rc-component/cascader/-/cascader-1.22.0.tgz#eec0b6f4d2df5903aa12cfed321a578705926937"
integrity sha512-SffrA57aS9oub3VuI7ajPhJTPtaNxngSvtRhD40Rd8dwJ5vfWPSrVanWgeepdWFGBt7EHftIK5RUU0u3rCTwWw==
dependencies:
"@rc-component/select" "~1.8.0"
"@rc-component/tree" "~1.3.2"
"@rc-component/select" "~1.10.0"
"@rc-component/tree" "~1.4.0"
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
@@ -3614,14 +3619,14 @@
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/image@~1.9.0":
version "1.9.0"
resolved "https://registry.yarnpkg.com/@rc-component/image/-/image-1.9.0.tgz#110785d735d20336afcdbac84e8fbfd059a7a44e"
integrity sha512-khF7w7xkBH5B1bsBcI1FSUZdkyd1aqpl2eYyILCqCzzQH3XdfehGUaZTnptyaJJfs09/R5hv9jXWyazOMFIClQ==
"@rc-component/image@~1.10.0":
version "1.10.0"
resolved "https://registry.yarnpkg.com/@rc-component/image/-/image-1.10.0.tgz#5d7a82d20e4c91f75875ea64eb1dadd7af676b1d"
integrity sha512-BjeZCRQ+hw+4WAhvrw8rJvy5fckA2xpf/X2XQEOABUHvLTNB9inB98X3Mp54jYQ7g10DfWERQWHXeC4ylxp1Uw==
dependencies:
"@rc-component/motion" "^1.0.0"
"@rc-component/portal" "^2.1.2"
"@rc-component/util" "^1.10.1"
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/input-number@~1.6.2":
@@ -3633,7 +3638,7 @@
"@rc-component/util" "^1.4.0"
clsx "^2.1.1"
"@rc-component/input@~1.3.0", "@rc-component/input@~1.3.1":
"@rc-component/input@~1.3.1":
version "1.3.1"
resolved "https://registry.yarnpkg.com/@rc-component/input/-/input-1.3.1.tgz#230b8b59cdde8521d50f0eede63ddacb61cc0cd3"
integrity sha512-iFvTUT9W+JC/MSin2aGAk8NqsVlTzcExNC9DZariON1IWirju9NoNeEk47an4Q8iHazkoVI/y1LnDi88+CPcig==
@@ -3642,15 +3647,27 @@
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/mentions@~1.10.0":
version "1.10.0"
resolved "https://registry.yarnpkg.com/@rc-component/mentions/-/mentions-1.10.0.tgz#46b1117cfb0c716b476e97f342555eccc2f41c97"
integrity sha512-CI1njYUVY0NjHtLhNoVmXlJyy568Sfep9Wsak6vmGjtT6uazx98djGYlCXz2xkHhEm73g91Y3MTvzUyE5avI7w==
"@rc-component/listy@~1.2.3":
version "1.2.3"
resolved "https://registry.yarnpkg.com/@rc-component/listy/-/listy-1.2.3.tgz#e9c8ef4f409c231b44dded37e63ae2875bbe0334"
integrity sha512-IXiMjV5s0rczLBlfh7G5nB4M3365mrEeedjwKtf5I+Ns3PqRUsebR2h5u8CeFarsVfLUPC2I5p0h09TNoOWyvQ==
dependencies:
"@rc-component/input" "~1.3.0"
"@rc-component/motion" "^1.1.4"
"@rc-component/portal" "^2.0.0"
"@rc-component/resize-observer" "^1.0.0"
"@rc-component/util" "^1.3.1"
"@rc-component/virtual-list" "^1.4.0"
clsx "^2.1.1"
"@rc-component/mentions@~1.11.0":
version "1.11.0"
resolved "https://registry.yarnpkg.com/@rc-component/mentions/-/mentions-1.11.0.tgz#cee0c4710f26766ad8550d386cfec5ff86fd58d9"
integrity sha512-IC2qXuEBMFHxPIXEFfYWj6Sr7UiDZnOqJHCYQBbwPzopBJOPZIR6mV9U4QH1bYQRlKYlYnIsajWDMgVGgWQyWQ==
dependencies:
"@rc-component/input" "~1.3.1"
"@rc-component/menu" "~1.4.0"
"@rc-component/trigger" "^3.0.0"
"@rc-component/util" "^1.3.0"
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/menu@~1.4.0", "@rc-component/menu@~1.4.1":
@@ -3724,7 +3741,7 @@
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/portal@^2.1.0", "@rc-component/portal@^2.1.2", "@rc-component/portal@^2.1.3", "@rc-component/portal@^2.2.0", "@rc-component/portal@^2.2.1":
"@rc-component/portal@^2.0.0", "@rc-component/portal@^2.1.0", "@rc-component/portal@^2.1.2", "@rc-component/portal@^2.1.3", "@rc-component/portal@^2.2.0", "@rc-component/portal@^2.2.1":
version "2.2.1"
resolved "https://registry.yarnpkg.com/@rc-component/portal/-/portal-2.2.1.tgz#37c34b4c8cd73f53cc7072c96dd0e9ac332669ec"
integrity sha512-ck+r1kW/JSv0wxPji3KN2ss9K6Z0qqwusw/mf/0JobXhZ8hC2ejZwCJObW/SvDi0uhA0VzmCnx0CaCci95tcmA==
@@ -3772,10 +3789,10 @@
"@rc-component/util" "^1.3.0"
clsx "^2.1.1"
"@rc-component/select@~1.8.0", "@rc-component/select@~1.8.2":
version "1.8.2"
resolved "https://registry.yarnpkg.com/@rc-component/select/-/select-1.8.2.tgz#f016992dae5c57186535512d73783e2fc7e4c59e"
integrity sha512-HQ9zuYqjfZTlcEMWlU1GAPBajd2OHIMVHyjZSGVTCVARwkfCgvXZMTEn0cduy3L+ejAKkaZluOQvxovZoaJaQw==
"@rc-component/select@~1.10.0":
version "1.10.1"
resolved "https://registry.yarnpkg.com/@rc-component/select/-/select-1.10.1.tgz#323b2f458a637e8e752f8341094783741c613c34"
integrity sha512-H+yQsl+qED9NilQ3g6zdpsMwUgwVjrcMTkNHAWRVU/MoNCYgTbDgU+MIMgZDK+rVdd2JUfI/MkysMcZZ0cyQKw==
dependencies:
"@rc-component/overflow" "^1.0.0"
"@rc-component/trigger" "^3.0.0"
@@ -3807,10 +3824,10 @@
"@rc-component/util" "^1.3.0"
clsx "^2.1.1"
"@rc-component/table@~1.10.4":
version "1.10.4"
resolved "https://registry.yarnpkg.com/@rc-component/table/-/table-1.10.4.tgz#8c4e33bc150aa39f579c15426421348a789de326"
integrity sha512-HwoTnrwc29zeoXkXGhWqzJh8FIibGUxi1jM4LtoSzmR9d5Vv5osUQpZxnXKBP8iOCvyD6BQzZm1nXJRcnrxpAg==
"@rc-component/table@~1.11.0":
version "1.11.1"
resolved "https://registry.yarnpkg.com/@rc-component/table/-/table-1.11.1.tgz#7b5c2a7c26fd37b6a403082029b5a72fcb330a4d"
integrity sha512-OWdS6DMmeWb7bJBGqPxYZpQbzBlBiXZUu2sqo6Ii7Sjs9GeK1IsrXrWk26SL2c6KEseabswdxrRj7WUm9LdECw==
dependencies:
"@rc-component/context" "^2.0.1"
"@rc-component/resize-observer" "^1.0.0"
@@ -3818,10 +3835,10 @@
"@rc-component/virtual-list" "^1.0.1"
clsx "^2.1.1"
"@rc-component/tabs@~1.11.0":
version "1.11.0"
resolved "https://registry.yarnpkg.com/@rc-component/tabs/-/tabs-1.11.0.tgz#c157b2fadcdc2f3ab6c69d0098f73e03c6aa0c12"
integrity sha512-hA/drZYOVa/MMIb4M2fWf3yaTyTG4qVuIABmghvEhyfw2nBob5VTH69lMCDjSVKmgODjO6nWlCV+gVn3xBrj5Q==
"@rc-component/tabs@~1.12.0":
version "1.12.0"
resolved "https://registry.yarnpkg.com/@rc-component/tabs/-/tabs-1.12.0.tgz#41a1a77ed1afc4f1b8b727003a058c631aceea1b"
integrity sha512-XL7Kqy5fnUE2WTlO1/fCGrrfNlGFebdr7JseGkEIjzcVMAtIFQJ8sqCSOmxcXstjU6fonD/4rnhZHxj7sDTajQ==
dependencies:
"@rc-component/dropdown" "~1.0.0"
"@rc-component/menu" "~1.4.0"
@@ -3830,13 +3847,13 @@
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/tooltip@~1.4.0":
version "1.4.0"
resolved "https://registry.yarnpkg.com/@rc-component/tooltip/-/tooltip-1.4.0.tgz#c8cf15c6773218a5a36271467f06e663f99c28e7"
integrity sha512-8Rx5DCctIlLI4raR0I0xHjVTf1aF48+gKCNeAAo5bmF5VoR5YED+A/XEqzXv9KKqrJDRcd3Wndpxh2hyzrTtSg==
"@rc-component/tooltip@~1.5.0":
version "1.5.0"
resolved "https://registry.yarnpkg.com/@rc-component/tooltip/-/tooltip-1.5.0.tgz#422aa0760b310e0a1d0f9f7223e7f0d455de57a2"
integrity sha512-agQ/+mBqrEQfTX4D3KhQ7j+ZbX4/VHjoJ7Noa2wIdZ1/FbQTOd7Sn92rp+jtCoqAVTLUgSOydePIgZ204gi2EQ==
dependencies:
"@rc-component/trigger" "^3.7.1"
"@rc-component/util" "^1.3.0"
"@rc-component/trigger" "^3.10.0"
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/tour@~2.4.0":
@@ -3849,27 +3866,27 @@
"@rc-component/util" "^1.7.0"
clsx "^2.1.1"
"@rc-component/tree-select@~1.11.0":
version "1.11.0"
resolved "https://registry.yarnpkg.com/@rc-component/tree-select/-/tree-select-1.11.0.tgz#9080cdf1d28f2ddd6d8a4879b7aa90d3170f7db9"
integrity sha512-EhS0X0wtUhBfK4S5TlpSY3MR9ndPMGgujtt1PJW3Ej+ToAlnS/6ohYURtCoXBYGqazUwHmgQGVUDsfpVwhWPkg==
"@rc-component/tree-select@~1.16.0":
version "1.16.1"
resolved "https://registry.yarnpkg.com/@rc-component/tree-select/-/tree-select-1.16.1.tgz#dcaea96e396e98108cb29cc051840d4fbdda38cc"
integrity sha512-a1Oi6EJhqAhdOxxupdJi6fP0RPHMKn5TcfkX2+llaQ4lF4nwfH7b6SCHcnsybaa2s+pk1yZYwVyeOYkDnEBRdg==
dependencies:
"@rc-component/select" "~1.8.0"
"@rc-component/tree" "~1.3.2"
"@rc-component/select" "~1.10.0"
"@rc-component/tree" "~1.4.0"
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/tree@~1.3.2":
version "1.3.2"
resolved "https://registry.yarnpkg.com/@rc-component/tree/-/tree-1.3.2.tgz#4b0c13564314eff61ca948c18ef923b87c9d7e44"
integrity sha512-bJFj46wEkpBPnWyTm18XmgAgNQ/4YvprxMOPPY2a6rmhGJYxLuNKEFiL5Qej4Qctu9wHJm8WW+v2SYskafE0kA==
"@rc-component/tree@~1.4.0":
version "1.4.0"
resolved "https://registry.yarnpkg.com/@rc-component/tree/-/tree-1.4.0.tgz#c0031180e681389bf0bdcb867a0087525b45c8a9"
integrity sha512-dGsJGDJQedA0BqqVgj3F8BvHXTSZijyhTXdbAdkcx8lynzZkty/CV3Z3LOm/fxz+BCfl3dfGiAQpb7Q5XNvl0Q==
dependencies:
"@rc-component/motion" "^1.0.0"
"@rc-component/util" "^1.11.1"
"@rc-component/virtual-list" "^1.2.0"
clsx "^2.1.1"
"@rc-component/trigger@^3.0.0", "@rc-component/trigger@^3.10.1", "@rc-component/trigger@^3.6.15", "@rc-component/trigger@^3.7.1":
"@rc-component/trigger@^3.0.0", "@rc-component/trigger@^3.10.0", "@rc-component/trigger@^3.10.1", "@rc-component/trigger@^3.6.15":
version "3.10.1"
resolved "https://registry.yarnpkg.com/@rc-component/trigger/-/trigger-3.10.1.tgz#cb28e1bc0745a2af6897dd7ec774f9b56dc88f86"
integrity sha512-mXlDN0IXdtV8Yqqm8195ECCyrbmfvvfKvwVvSlH0+qvKD6BUF8gRhEjSy0FOcD1+CcDRHgTiX99LoxfQrmh3Cw==
@@ -3888,7 +3905,7 @@
"@rc-component/util" "^1.11.1"
clsx "^2.1.1"
"@rc-component/util@^1.10.1", "@rc-component/util@^1.11.0", "@rc-component/util@^1.11.1", "@rc-component/util@^1.12.0", "@rc-component/util@^1.2.0", "@rc-component/util@^1.2.1", "@rc-component/util@^1.3.0", "@rc-component/util@^1.4.0", "@rc-component/util@^1.7.0", "@rc-component/util@^1.9.0":
"@rc-component/util@^1.11.0", "@rc-component/util@^1.11.1", "@rc-component/util@^1.12.0", "@rc-component/util@^1.2.0", "@rc-component/util@^1.2.1", "@rc-component/util@^1.3.0", "@rc-component/util@^1.3.1", "@rc-component/util@^1.4.0", "@rc-component/util@^1.7.0", "@rc-component/util@^1.9.0":
version "1.12.0"
resolved "https://registry.yarnpkg.com/@rc-component/util/-/util-1.12.0.tgz#58e453585810bcb8a35ff1aafd5e01187457b86f"
integrity sha512-AEjPL8JVdohIITaiXokyjL9WQ6tKWWjAYK9QU16tGNE9JaQABBQy+hA4H2Lup5MgXy9yY3iLrbZJheuU13hTdQ==
@@ -3906,6 +3923,16 @@
"@rc-component/util" "^1.4.0"
clsx "^2.1.1"
"@rc-component/virtual-list@^1.4.0":
version "1.5.1"
resolved "https://registry.yarnpkg.com/@rc-component/virtual-list/-/virtual-list-1.5.1.tgz#71c5844a8d6bd5b3501dfb66419d3a4612b2bb18"
integrity sha512-boqHxdtyWC88u8quYgEO49bcBy5fzRiOcnBge+N4nLzs2k8hUQ/yw7JE9dM6yCBE4jSm5YSHVCVMS+suBuJGKA==
dependencies:
"@babel/runtime" "^8.0.0"
"@rc-component/resize-observer" "^1.0.1"
"@rc-component/util" "^1.4.0"
clsx "^2.1.1"
"@redocly/ajv@^8.18.1":
version "8.18.3"
resolved "https://registry.yarnpkg.com/@redocly/ajv/-/ajv-8.18.3.tgz#a925753d9a33375219f1b2ba91aef320f9929577"
@@ -5658,110 +5685,100 @@
dependencies:
"@types/yargs-parser" "*"
"@typescript-eslint/eslint-plugin@8.66.0", "@typescript-eslint/eslint-plugin@^8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.66.0.tgz#76e86aa5a2459fbf5bbd7a839c0dc0cce1d56224"
integrity sha512-p088eaGrzYz1s+7cov0aMOCkNGTJlVxF4jgubf28c8L0Cv9Rloj8YBHnv4hXLq6IIEE1AsjNWavO+k+8kP2Y0A==
"@typescript-eslint/eslint-plugin@8.67.0", "@typescript-eslint/eslint-plugin@^8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.67.0.tgz#52f9f0e47d5a7571c4336e69bfeea581509ef2cf"
integrity sha512-Un7Heoyj65NREbKAyIrFxeM143NZpExWmy1Nep4DLeQOeLlTeumPjoNKnBrU5D5moWXbPJgRa5Uwcdu0faVNGQ==
dependencies:
"@eslint-community/regexpp" "^4.12.2"
"@typescript-eslint/scope-manager" "8.66.0"
"@typescript-eslint/type-utils" "8.66.0"
"@typescript-eslint/utils" "8.66.0"
"@typescript-eslint/visitor-keys" "8.66.0"
"@typescript-eslint/scope-manager" "8.67.0"
"@typescript-eslint/type-utils" "8.67.0"
"@typescript-eslint/utils" "8.67.0"
"@typescript-eslint/visitor-keys" "8.67.0"
ignore "^7.0.5"
natural-compare "^1.4.0"
ts-api-utils "^2.5.0"
"@typescript-eslint/parser@8.66.0", "@typescript-eslint/parser@^8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/parser/-/parser-8.66.0.tgz#88e3865ecf73b0118134e7cb831da87a961a57a1"
integrity sha512-X6ypGChaWYk6PBtUg2BwuTZEFFcHJAtGTVJ9/lCTOufhZ4i9fNolQNnktq+kkMCwMj7V8Svsq7+TxSDslmhE0g==
"@typescript-eslint/parser@8.67.0", "@typescript-eslint/parser@^8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/parser/-/parser-8.67.0.tgz#0158022ec9927e0afcd58a8cc2ad57e01d892f5c"
integrity sha512-fUBfTuuEulWqX6V8+O3PtScV01tzYYRUDTAirHFKoRAt7nOzoGiPt0M/bB47wWNy0coOOcgEwAMUtBpykMxl6w==
dependencies:
"@typescript-eslint/scope-manager" "8.66.0"
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/typescript-estree" "8.66.0"
"@typescript-eslint/visitor-keys" "8.66.0"
"@typescript-eslint/scope-manager" "8.67.0"
"@typescript-eslint/types" "8.67.0"
"@typescript-eslint/typescript-estree" "8.67.0"
"@typescript-eslint/visitor-keys" "8.67.0"
debug "^4.4.3"
"@typescript-eslint/project-service@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/project-service/-/project-service-8.66.0.tgz#828f788895df52d9eb2b543445a3a5a13e35ab4e"
integrity sha512-7MthGPTt4BP69lSryqpqq8HQqxuzynssckL/jyDyk3+TNMQ3y2jFWkptCrktWvBrP+EH787Nl5N5Qpw7WZg+5g==
"@typescript-eslint/project-service@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/project-service/-/project-service-8.67.0.tgz#1552db007ca9206a1c6c7acf49e210bd17a8c56f"
integrity sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==
dependencies:
"@typescript-eslint/tsconfig-utils" "^8.66.0"
"@typescript-eslint/types" "^8.66.0"
"@typescript-eslint/tsconfig-utils" "^8.67.0"
"@typescript-eslint/types" "^8.67.0"
debug "^4.4.3"
"@typescript-eslint/scope-manager@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/scope-manager/-/scope-manager-8.66.0.tgz#4fffcc6ebd0df9fe7983c0256967567ea6f5ac63"
integrity sha512-8TGcH25j9zqJ/IULB/ppyhRvxA8QYfFEZ7nfbg6/BN9spDgb8fPWQXlE5l8TWBL50EtUx007uZ1o9VOwrq2/9g==
"@typescript-eslint/scope-manager@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/scope-manager/-/scope-manager-8.67.0.tgz#4d4c2da09560d10dd7d947cba2d29d14d25af16d"
integrity sha512-EgvsleTwS4E+WzzSvem8fAUubLwatMNF1B5hHSLQxcvs7q2dtRhGyujHwLJSYlG41niJ7GP24Aha2+0mb1b2kg==
dependencies:
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/visitor-keys" "8.66.0"
"@typescript-eslint/types" "8.67.0"
"@typescript-eslint/visitor-keys" "8.67.0"
"@typescript-eslint/tsconfig-utils@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.66.0.tgz#3a89066c507aa30541dc176804685b4b444e1e52"
integrity sha512-9D5gLYZG4rOjcoag8MQ/fWI8WqA9wcPDyOGyWtWFhvM1lHRbliqUSPIY5J3zqCU1tvSwzXxnnjhQhz5Ne7mJ4g==
"@typescript-eslint/tsconfig-utils@^8.66.0":
"@typescript-eslint/tsconfig-utils@8.67.0", "@typescript-eslint/tsconfig-utils@^8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz#f45a3eba6b9132fb47141ec03ce2f275f1ea991d"
integrity sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==
"@typescript-eslint/type-utils@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/type-utils/-/type-utils-8.66.0.tgz#b2315303eca72fad9afa7be4f58f053c8f2a0479"
integrity sha512-LG2dWfjZQQp0ADtAu/EWJVayefGL2UEZ3CDeI44D9v3rXB/WYUqE/jpO28KrEKul5AySrmI+Zh1v6v+xW2U9+g==
"@typescript-eslint/type-utils@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/type-utils/-/type-utils-8.67.0.tgz#96bed105275559df3bcf0449b73a6414d35c59ce"
integrity sha512-aVWDXbRmdXO9siTfX4ditQI1T9+zVcNazT48EJCD0v40/9RIFoUgZ05CmGEq9H2gixRpjUn/iplwvlcvutJW/Q==
dependencies:
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/typescript-estree" "8.66.0"
"@typescript-eslint/utils" "8.66.0"
"@typescript-eslint/types" "8.67.0"
"@typescript-eslint/typescript-estree" "8.67.0"
"@typescript-eslint/utils" "8.67.0"
debug "^4.4.3"
ts-api-utils "^2.5.0"
"@typescript-eslint/types@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/types/-/types-8.66.0.tgz#3cacab94d3b564c1d48c56eb37b89f89a6d48479"
integrity sha512-H6gcYaSDOyvL3AD/jHUtUFo2jqGgn/F6nuyuZSu0QTesxL+cP4dQoIMrODRofuJC09g64+WgZ6tE19Y1N2YIFQ==
"@typescript-eslint/types@^8.66.0":
"@typescript-eslint/types@8.67.0", "@typescript-eslint/types@^8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/types/-/types-8.67.0.tgz#4a8d00cc1faba5c14feabc60f85b7a32652f34b6"
integrity sha512-sBtgslww8nsMYUjhdPBiSyUqSzT8uR6g93A2QXnQC8+cGdjz0CyaOdqHDRJb1AtORbZCNUJBBeFA/tNR2uQmww==
"@typescript-eslint/typescript-estree@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/typescript-estree/-/typescript-estree-8.66.0.tgz#1a38c3a97dc6c669b66d585d7f90ebc4fbb32a50"
integrity sha512-8/x4INiiQb10jGgXYD7116/zQ+OL84ZIFn0za68wwFHCanT/VLbBEroWht8RV8fn0/ZCAoazHLQgwUC0UQcDfg==
"@typescript-eslint/typescript-estree@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz#116c3a47c06119c5a050e8851861d6497dd64bc2"
integrity sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==
dependencies:
"@typescript-eslint/project-service" "8.66.0"
"@typescript-eslint/tsconfig-utils" "8.66.0"
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/visitor-keys" "8.66.0"
"@typescript-eslint/project-service" "8.67.0"
"@typescript-eslint/tsconfig-utils" "8.67.0"
"@typescript-eslint/types" "8.67.0"
"@typescript-eslint/visitor-keys" "8.67.0"
debug "^4.4.3"
minimatch "^10.2.2"
semver "^7.7.3"
tinyglobby "^0.2.15"
ts-api-utils "^2.5.0"
"@typescript-eslint/utils@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/utils/-/utils-8.66.0.tgz#e277d67427043cdca2580ee91aa62921e4689969"
integrity sha512-jasearZPolBw5NJNYGMwxzHMF83niVWmMU1VdHzG1CyfI2VS7f7nZltnKtHcg20hW+7Uo5GfK4MeDPoU3qI8EA==
"@typescript-eslint/utils@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/utils/-/utils-8.67.0.tgz#3e478a3d69d330a1fc50c12746cc2ee0732ccfcd"
integrity sha512-U9D1FdwEWBwok3hxxSdhclMb0twvt9QnjIQ0VfQ1AiX2epnpSgv2ubVDsayOFyY8K6FX+AQ7E0FKWVG3iKsj1A==
dependencies:
"@eslint-community/eslint-utils" "^4.9.1"
"@typescript-eslint/scope-manager" "8.66.0"
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/typescript-estree" "8.66.0"
"@typescript-eslint/scope-manager" "8.67.0"
"@typescript-eslint/types" "8.67.0"
"@typescript-eslint/typescript-estree" "8.67.0"
"@typescript-eslint/visitor-keys@8.66.0":
version "8.66.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/visitor-keys/-/visitor-keys-8.66.0.tgz#4c494e94745fb2724a4f37a310091e56b644d18a"
integrity sha512-dkKR8q+lKciskj1Y3vthHktl+3cMLWGyVUP23bRiPZ5O9BRT++4EqDDV+TVeIKBL1VXVEqrJlz8MYbcnvJcAlg==
"@typescript-eslint/visitor-keys@8.67.0":
version "8.67.0"
resolved "https://registry.yarnpkg.com/@typescript-eslint/visitor-keys/-/visitor-keys-8.67.0.tgz#601d40af9acf82a28da2286f3edafc69bba9017f"
integrity sha512-fkv8dHRDqfGtTHuJeebdrQ7cX6Ad4WAS00rgHh9UGvMycF1mjBfsxry1XsLIFhWZ6Judlh6UdzK+TYlbpCXgnA==
dependencies:
"@typescript-eslint/types" "8.66.0"
"@typescript-eslint/types" "8.67.0"
eslint-visitor-keys "^5.0.0"
"@ungap/structured-clone@^1.0.0":
@@ -6164,10 +6181,10 @@ ansis@^3.2.0:
resolved "https://registry.yarnpkg.com/ansis/-/ansis-3.17.0.tgz#fa8d9c2a93fe7d1177e0c17f9eeb562a58a832d7"
integrity sha512-0qWUglt9JEqLFr3w1I1pbrChn1grhaiAR2ocX1PP/flRmxgtwTzPFFFnfIlD6aMOLQZgSuCRlidD70lvx8yhzg==
antd@^6.5.4:
version "6.5.4"
resolved "https://registry.yarnpkg.com/antd/-/antd-6.5.4.tgz#b41665e86a5f46ca761abd3b0abef7460116ca0d"
integrity sha512-jchA6i0rEwHjLpgC+l6HeLHP0gL4Q4yjs6Mxqt6PlhGD5ArxCj3ZH+fKFbNquCtd6Rlzzi+emfNFpP2dGLwZzg==
antd@^6.6.0:
version "6.6.0"
resolved "https://registry.yarnpkg.com/antd/-/antd-6.6.0.tgz#8acb84c54b36594b5c1a9084c8acb6a03b79961b"
integrity sha512-UDwWIbpmrCHB9ZQ+bPh4vQfB6DTI2ulIyoQ0Tc9xxalFblttiNGHl3ySBD9SyV/8+gUjFzfSx1+iU1Fog2i46w==
dependencies:
"@ant-design/colors" "^8.0.1"
"@ant-design/cssinjs" "^2.1.2"
@@ -6176,7 +6193,7 @@ antd@^6.5.4:
"@ant-design/icons" "^6.3.2"
"@ant-design/react-slick" "~2.0.0"
"@babel/runtime" "^7.29.2"
"@rc-component/cascader" "~1.17.0"
"@rc-component/cascader" "~1.22.0"
"@rc-component/checkbox" "~2.0.0"
"@rc-component/collapse" "~1.2.0"
"@rc-component/color-picker" "~3.1.1"
@@ -6184,10 +6201,11 @@ antd@^6.5.4:
"@rc-component/drawer" "~1.4.2"
"@rc-component/dropdown" "~1.0.3"
"@rc-component/form" "~1.8.6"
"@rc-component/image" "~1.9.0"
"@rc-component/image" "~1.10.0"
"@rc-component/input" "~1.3.1"
"@rc-component/input-number" "~1.6.2"
"@rc-component/mentions" "~1.10.0"
"@rc-component/listy" "~1.2.3"
"@rc-component/mentions" "~1.11.0"
"@rc-component/menu" "~1.4.1"
"@rc-component/motion" "^1.3.3"
"@rc-component/mutate-observer" "^2.0.1"
@@ -6199,16 +6217,16 @@ antd@^6.5.4:
"@rc-component/rate" "~1.0.1"
"@rc-component/resize-observer" "^1.1.2"
"@rc-component/segmented" "~1.3.0"
"@rc-component/select" "~1.8.2"
"@rc-component/select" "~1.10.0"
"@rc-component/slider" "~1.1.1"
"@rc-component/steps" "~1.2.2"
"@rc-component/switch" "~1.0.3"
"@rc-component/table" "~1.10.4"
"@rc-component/tabs" "~1.11.0"
"@rc-component/tooltip" "~1.4.0"
"@rc-component/table" "~1.11.0"
"@rc-component/tabs" "~1.12.0"
"@rc-component/tooltip" "~1.5.0"
"@rc-component/tour" "~2.4.0"
"@rc-component/tree" "~1.3.2"
"@rc-component/tree-select" "~1.11.0"
"@rc-component/tree" "~1.4.0"
"@rc-component/tree-select" "~1.16.0"
"@rc-component/trigger" "^3.10.1"
"@rc-component/upload" "~1.1.1"
"@rc-component/util" "^1.12.0"
@@ -7996,10 +8014,10 @@ doctrine@^2.1.0:
dependencies:
esutils "^2.0.2"
docusaurus-plugin-openapi-docs@^5.1.3:
version "5.1.3"
resolved "https://registry.yarnpkg.com/docusaurus-plugin-openapi-docs/-/docusaurus-plugin-openapi-docs-5.1.3.tgz#b8cd5f8451aaf881deb1a744a8295685f1681865"
integrity sha512-HnpblSBdXoR39VNTIW9zWERUsMJxXOpvdQoBKyaTkUBPwCM48Z76+ndo2yO2vADq+EhWjJlfxL1DUzCrgNjThQ==
docusaurus-plugin-openapi-docs@^5.2.0:
version "5.2.0"
resolved "https://registry.yarnpkg.com/docusaurus-plugin-openapi-docs/-/docusaurus-plugin-openapi-docs-5.2.0.tgz#8318ec90cd21fed023be57696211af7d72fd81db"
integrity sha512-MjrfRAMB64uvdxRVz6L9AXWe4QFjCdoBAzYs306yyI3nnXHsFj2lv2FnLA90JV9CAUZaGiYMvvkzBo2Nrkq/9w==
dependencies:
"@apidevtools/json-schema-ref-parser" "^15.3.3"
"@redocly/openapi-core" "^2.25.2"
@@ -8017,10 +8035,10 @@ docusaurus-plugin-openapi-docs@^5.1.3:
swagger2openapi "^7.0.8"
xml-formatter "^3.6.6"
docusaurus-theme-openapi-docs@^5.1.3:
version "5.1.3"
resolved "https://registry.yarnpkg.com/docusaurus-theme-openapi-docs/-/docusaurus-theme-openapi-docs-5.1.3.tgz#e23644a63785352abbc76e42760c0dfdff3669e1"
integrity sha512-npbD1QahtjAEmrOet/86i5fTmcJX4/rPhVT+c0qKjm7StUNbyqjwchSVBQuU1rB69T51JOA9TpT/y6QcB9Xjvw==
docusaurus-theme-openapi-docs@^5.2.0:
version "5.2.0"
resolved "https://registry.yarnpkg.com/docusaurus-theme-openapi-docs/-/docusaurus-theme-openapi-docs-5.2.0.tgz#6d93a74e2e3cf0ae77d24e1c4144bd2e74a52115"
integrity sha512-L0b80LzaMUfr76a9EQXRPCf8nxkEz8Xo6Aknnke1UeE2oXsgoiVki6U+RTE7GmJRjO8zSNKXyckGmGmqqWuHeA==
dependencies:
"@hookform/error-message" "^2.0.1"
"@reduxjs/toolkit" "^2.8.2"
@@ -8105,7 +8123,7 @@ domhandler@^5.0.2, domhandler@^5.0.3:
dependencies:
domelementtype "^2.3.0"
dompurify@^3.3.3, dompurify@^3.4.12:
dompurify@^3.3.3, dompurify@^3.4.13:
version "3.4.13"
resolved "https://registry.yarnpkg.com/dompurify/-/dompurify-3.4.13.tgz#fc28949d59f92d62e28a3a764bcbeee35897a1be"
integrity sha512-2vmYIoqjze2d+kakP8S/nS5shfsl587kzwEjcGlTdiksUVgFHnFCsLYDVj/JNqJVOQZGSYBTmuycv0PodwmnMQ==
@@ -9156,10 +9174,10 @@ globals@^14.0.0:
resolved "https://registry.yarnpkg.com/globals/-/globals-14.0.0.tgz#898d7413c29babcf6bafe56fcadded858ada724e"
integrity sha512-oahGvuMGQlPw/ivIYBjVSrWAfWLBeku5tpPE2fOPLi+WHffIWbuh2tCjhyQhTBPMf5E9jDEH4FOmTYgYwbKwtQ==
globals@^17.9.0:
version "17.9.0"
resolved "https://registry.yarnpkg.com/globals/-/globals-17.9.0.tgz#e43f252d6bbe71508da43902a1709c8895a59f70"
integrity sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==
globals@^17.10.0:
version "17.10.0"
resolved "https://registry.yarnpkg.com/globals/-/globals-17.10.0.tgz#f9dbd847ae99e236f98b13095e2426ac3b25a45c"
integrity sha512-V0kztuWST2k8A/VbxAY8+L+7+Rgo3fyA24IHRLrZp7HOzJjV0gHSaZUjK9lpP/IrBSNite2tZ1prhRkinRu1CA==
globalthis@^1.0.4:
version "1.0.4"
@@ -10266,10 +10284,10 @@ js-levenshtein@^1.1.6:
resolved "https://registry.yarnpkg.com/js-tokens/-/js-tokens-4.0.0.tgz#19203fb59991df98e3a287050d4647cdeaf32499"
integrity sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==
js-yaml@4.1.0, js-yaml@=4.3.0, js-yaml@^4.1.0, js-yaml@^4.1.1, js-yaml@^4.2.0, js-yaml@^4.3.0:
version "4.3.0"
resolved "https://registry.yarnpkg.com/js-yaml/-/js-yaml-4.3.0.tgz#d1900572a7f7cf0b5f540c83673e60bad3436592"
integrity sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==
js-yaml@4.1.0, js-yaml@=4.3.1, js-yaml@^4.1.0, js-yaml@^4.1.1, js-yaml@^4.2.0, js-yaml@^4.3.0:
version "4.3.1"
resolved "https://registry.yarnpkg.com/js-yaml/-/js-yaml-4.3.1.tgz#01216c001d67f48e2cd560d708c7af21090a3848"
integrity sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==
dependencies:
argparse "^2.0.1"
@@ -12244,32 +12262,32 @@ oxc-resolver@^11.19.1:
"@oxc-resolver/binding-win32-arm64-msvc" "11.23.0"
"@oxc-resolver/binding-win32-x64-msvc" "11.23.0"
oxfmt@^0.62.0:
version "0.62.0"
resolved "https://registry.yarnpkg.com/oxfmt/-/oxfmt-0.62.0.tgz#9945728022d26dc0a1d5bc486db112e7e340507a"
integrity sha512-vxgGHTmnDU9j4CX7dDBLzxgmHxfda/yPcgJkGCMUSCwRmz+euo/V08xXLNgXTeqAB9Fhf3Pe2nO1RNKLCVgphQ==
oxfmt@^0.63.0:
version "0.63.0"
resolved "https://registry.yarnpkg.com/oxfmt/-/oxfmt-0.63.0.tgz#c7338e6c43a68d5cf8dc61c08b617d77cb54e323"
integrity sha512-kgdDwv35wvVf6554U2Ab8Jnd0zTM+TsEQWwaB70RAjK3gICFAFGO+2Hd3Be27GMoXj3XRL9IKSNRVl7KBQL6iw==
dependencies:
tinypool "2.1.0"
optionalDependencies:
"@oxfmt/binding-android-arm-eabi" "0.62.0"
"@oxfmt/binding-android-arm64" "0.62.0"
"@oxfmt/binding-darwin-arm64" "0.62.0"
"@oxfmt/binding-darwin-x64" "0.62.0"
"@oxfmt/binding-freebsd-x64" "0.62.0"
"@oxfmt/binding-linux-arm-gnueabihf" "0.62.0"
"@oxfmt/binding-linux-arm-musleabihf" "0.62.0"
"@oxfmt/binding-linux-arm64-gnu" "0.62.0"
"@oxfmt/binding-linux-arm64-musl" "0.62.0"
"@oxfmt/binding-linux-ppc64-gnu" "0.62.0"
"@oxfmt/binding-linux-riscv64-gnu" "0.62.0"
"@oxfmt/binding-linux-riscv64-musl" "0.62.0"
"@oxfmt/binding-linux-s390x-gnu" "0.62.0"
"@oxfmt/binding-linux-x64-gnu" "0.62.0"
"@oxfmt/binding-linux-x64-musl" "0.62.0"
"@oxfmt/binding-openharmony-arm64" "0.62.0"
"@oxfmt/binding-win32-arm64-msvc" "0.62.0"
"@oxfmt/binding-win32-ia32-msvc" "0.62.0"
"@oxfmt/binding-win32-x64-msvc" "0.62.0"
"@oxfmt/binding-android-arm-eabi" "0.63.0"
"@oxfmt/binding-android-arm64" "0.63.0"
"@oxfmt/binding-darwin-arm64" "0.63.0"
"@oxfmt/binding-darwin-x64" "0.63.0"
"@oxfmt/binding-freebsd-x64" "0.63.0"
"@oxfmt/binding-linux-arm-gnueabihf" "0.63.0"
"@oxfmt/binding-linux-arm-musleabihf" "0.63.0"
"@oxfmt/binding-linux-arm64-gnu" "0.63.0"
"@oxfmt/binding-linux-arm64-musl" "0.63.0"
"@oxfmt/binding-linux-ppc64-gnu" "0.63.0"
"@oxfmt/binding-linux-riscv64-gnu" "0.63.0"
"@oxfmt/binding-linux-riscv64-musl" "0.63.0"
"@oxfmt/binding-linux-s390x-gnu" "0.63.0"
"@oxfmt/binding-linux-x64-gnu" "0.63.0"
"@oxfmt/binding-linux-x64-musl" "0.63.0"
"@oxfmt/binding-openharmony-arm64" "0.63.0"
"@oxfmt/binding-win32-arm64-msvc" "0.63.0"
"@oxfmt/binding-win32-ia32-msvc" "0.63.0"
"@oxfmt/binding-win32-x64-msvc" "0.63.0"
p-cancelable@^3.0.0:
version "3.0.0"
@@ -15085,10 +15103,10 @@ swagger-client@^3.37.8:
"@swagger-api/apidom-parser-adapter-openapi-yaml-3-2" "^1.12.0"
"@swagger-api/apidom-parser-adapter-yaml-1-2" "^1.12.0"
swagger-ui-react@^5.32.12:
version "5.32.12"
resolved "https://registry.yarnpkg.com/swagger-ui-react/-/swagger-ui-react-5.32.12.tgz#47525a26774eb02db0e6203af72f5b32fa6205cc"
integrity sha512-WCdkNOQyMTZDu+z356FpwVWHf1dwZgQPUjdQPh1L4r7jULaJTKKlIItXq6WsZdYeXvsHndMdxxccEQXOAroUHQ==
swagger-ui-react@^5.32.13:
version "5.32.13"
resolved "https://registry.yarnpkg.com/swagger-ui-react/-/swagger-ui-react-5.32.13.tgz#04c96140b0a2d4ea01ebec4d4cfc655d5ed9a500"
integrity sha512-XIDl+Ny6kE1N8wpSPiOFrjPfAevs4GR4XmV6BT6NLMikkMFIbIVocWbA8pnKYyYXQe8Rccfli5o2zDfySw0FnQ==
dependencies:
"@babel/runtime-corejs3" "^7.27.1"
"@scarf/scarf" "=1.4.0"
@@ -15097,11 +15115,11 @@ swagger-ui-react@^5.32.12:
classnames "^2.5.1"
css.escape "1.5.1"
deep-extend "0.6.0"
dompurify "^3.4.12"
dompurify "^3.4.13"
ieee754 "^1.2.1"
immutable "^4.3.9"
js-file-download "^0.4.12"
js-yaml "=4.3.0"
js-yaml "=4.3.1"
lodash "^4.18.1"
prop-types "^15.8.1"
randexp "^0.5.3"
@@ -15467,15 +15485,15 @@ types-ramda@^0.30.1:
dependencies:
ts-toolbelt "^9.6.0"
typescript-eslint@^8.66.0:
version "8.66.0"
resolved "https://registry.yarnpkg.com/typescript-eslint/-/typescript-eslint-8.66.0.tgz#0809b6d25c8a0924690ba30dc1f05607093c11fb"
integrity sha512-QlEbBPz/RuJ1XUHj29nm3t0F/O/cSlEnntozqPOYHnnTGAXFamnMBu5i9Vn6vhUPHGAjR+Vl+5J8vPN/BMUrJw==
typescript-eslint@^8.67.0:
version "8.67.0"
resolved "https://registry.yarnpkg.com/typescript-eslint/-/typescript-eslint-8.67.0.tgz#1e92de09ee0ff2d96cc0848f5e9f345ea930d963"
integrity sha512-S2udFs8tCKEKffuJ4TB1idGUZiXdCPGi3IPBGWXarbLQ5UPXORV8QEVzJ4gCRduURMb5EkpNCdjbk0eDIuI8Yg==
dependencies:
"@typescript-eslint/eslint-plugin" "8.66.0"
"@typescript-eslint/parser" "8.66.0"
"@typescript-eslint/typescript-estree" "8.66.0"
"@typescript-eslint/utils" "8.66.0"
"@typescript-eslint/eslint-plugin" "8.67.0"
"@typescript-eslint/parser" "8.67.0"
"@typescript-eslint/typescript-estree" "8.67.0"
"@typescript-eslint/utils" "8.67.0"
typescript@~6.0.3:
version "6.0.3"
+332 -609
View File
File diff suppressed because it is too large Load Diff
+6 -6
View File
@@ -158,7 +158,7 @@
"@visx/xychart": "^4.0.0",
"ag-grid-community": "36.1.0",
"ag-grid-react": "36.1.0",
"antd": "^6.5.4",
"antd": "^6.6.0",
"chrono-node": "^2.10.1",
"classnames": "^2.2.5",
"content-disposition": "^2.0.1",
@@ -176,7 +176,7 @@
"geostyler-openlayers-parser": "^5.7.1",
"geostyler-style": "11.0.2",
"geostyler-wfs-parser": "^3.0.1",
"google-auth-library": "^11.0.0",
"google-auth-library": "^11.0.1",
"immer": "^11.1.16",
"interweave": "^13.1.1",
"jquery": "^4.0.0",
@@ -263,7 +263,7 @@
"@storybook/test-runner": "0.24.4",
"@svgr/webpack": "^8.1.0",
"@swc/core": "^1.15.47",
"@swc/plugin-emotion": "^14.15.0",
"@swc/plugin-emotion": "^14.19.0",
"@swc/plugin-transform-imports": "^12.5.0",
"@testing-library/dom": "^10.4.1",
"@testing-library/jest-dom": "^7.0.1",
@@ -289,7 +289,7 @@
"@types/rison": "0.1.0",
"@types/tinycolor2": "^1.4.3",
"@types/unzipper": "^0.10.11",
"@typescript-eslint/eslint-plugin": "^8.66.0",
"@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.63.0",
"babel-jest": "^30.4.1",
"babel-loader": "^10.1.1",
@@ -331,8 +331,8 @@
"mini-css-extract-plugin": "^2.10.2",
"minimizer-webpack-plugin": "^5.6.1",
"open-cli": "^9.0.0",
"oxfmt": "^0.62.0",
"oxlint": "^1.77.0",
"oxfmt": "^0.63.0",
"oxlint": "^1.78.0",
"po2json": "^0.4.5",
"postcss-styled-syntax": "^0.7.2",
"process": "^0.11.10",
@@ -130,6 +130,7 @@ export enum GenericDataType {
String = 1,
Temporal = 2,
Boolean = 3,
MultiValue = 4,
}
/**
@@ -28,6 +28,7 @@ import {
FieldBinaryOutlined,
FieldStringOutlined,
NumberOutlined,
UnorderedListOutlined,
} from '@ant-design/icons';
import { Icons } from '@superset-ui/core/components';
@@ -72,6 +73,10 @@ export function ColumnTypeLabel({ type }: ColumnTypeLabelProps) {
typeIcon = <FieldBinaryOutlined aria-label={t('boolean type icon')} />;
} else if (type === GenericDataType.Temporal) {
typeIcon = <ClockCircleOutlined aria-label={t('temporal type icon')} />;
} else if (type === GenericDataType.MultiValue) {
typeIcon = (
<UnorderedListOutlined aria-label={t('multi-value type icon')} />
);
}
return <TypeIconWrapper>{typeIcon}</TypeIconWrapper>;
@@ -64,4 +64,21 @@ describe('ColumnOption', () => {
renderColumnTypeLabel({ type: GenericDataType.Temporal });
expect(screen.getByLabelText('temporal type icon')).toBeVisible();
});
test('multi-value (array) type shows list icon', () => {
renderColumnTypeLabel({ type: GenericDataType.MultiValue });
expect(screen.getByLabelText('multi-value type icon')).toBeVisible();
});
});
describe('GenericDataType enum parity', () => {
// These numeric values are shared with the backend enum in
// superset/utils/core.py (GenericDataType). They must stay in sync because
// the backend serializes columns using these integers.
test('values match the backend contract', () => {
expect(GenericDataType.Numeric).toBe(0);
expect(GenericDataType.String).toBe(1);
expect(GenericDataType.Temporal).toBe(2);
expect(GenericDataType.Boolean).toBe(3);
expect(GenericDataType.MultiValue).toBe(4);
});
});
@@ -107,12 +107,14 @@ const getAllSelectOptions = () =>
const findSelectOption = (text: string) =>
waitFor(() =>
within(getElementByClassName('.rc-virtual-list')).getByText(text),
within(getElementByClassName('.ant-select-dropdown-list')).getByText(text),
);
const querySelectOption = (text: string) =>
waitFor(() =>
within(getElementByClassName('.rc-virtual-list')).queryByText(text),
within(getElementByClassName('.ant-select-dropdown-list')).queryByText(
text,
),
);
const findAllSelectOptions = () =>
@@ -644,7 +646,7 @@ test('does not add a new option if the option already exists', async () => {
await type(option);
await waitFor(() => {
const array = within(
getElementByClassName('.rc-virtual-list'),
getElementByClassName('.ant-select-dropdown-list'),
).getAllByText(option);
expect(array.length).toBe(1);
});
@@ -1398,7 +1400,7 @@ test('appends page>1 results during an active search and discards them when sear
// scrollTop via e.currentTarget in its onFallbackScroll handler, which
// then forwards to onPopupScroll (handlePagination here).
const holder = document.querySelector(
'.rc-virtual-list-holder',
'.ant-select-dropdown-list-holder',
) as HTMLElement | null;
if (!holder) throw new Error('virtual-list holder not rendered');
Object.defineProperty(holder, 'scrollHeight', {
@@ -93,12 +93,14 @@ const deselectAllButtonText = (length: number) =>
const findSelectOption = (text: string) =>
waitFor(() =>
within(getElementByClassName('.rc-virtual-list')).getByText(text),
within(getElementByClassName('.ant-select-dropdown-list')).getByText(text),
);
const querySelectOption = (text: string) =>
waitFor(() =>
within(getElementByClassName('.rc-virtual-list')).queryByText(text),
within(getElementByClassName('.ant-select-dropdown-list')).queryByText(
text,
),
);
const getAllSelectOptions = () =>
@@ -19,19 +19,71 @@
import { t } from '@apache-superset/core/translation';
import { sanitizeHtml } from './html';
export type TooltipTruncationMode = 'off' | 'end' | 'start' | 'middle';
export const TRUNCATION_MAX_CHARS = 40;
const TRUNCATION_STYLE = `
max-width: 300px;
overflow: hidden;
text-overflow: ellipsis;
`;
const NOWRAP_STYLE = `
white-space: nowrap;
`;
/**
* Shortens plain text so a tooltip label stays readable, placing the ellipsis
* where the caller asked for it.
*
* Only 'start' and 'middle' slice. 'end' is handled by CSS in tooltipHtml, and
* 'off' means no truncation at all, so both return the input untouched.
*
* The input must be plain text. Callers are responsible for truncating before
* any markup (such as the ECharts series marker) is prepended, and before
* sanitization slicing a string that already contains markup would cut into
* a tag.
*/
export function truncateLabel(
text: string,
mode: TooltipTruncationMode = 'end',
): string {
if (
(mode !== 'start' && mode !== 'middle') ||
text.length <= TRUNCATION_MAX_CHARS
) {
return text;
}
const budget = TRUNCATION_MAX_CHARS - 1;
if (mode === 'start') {
return `${text.slice(-budget)}`;
}
const head = Math.ceil(budget / 2);
const tail = Math.floor(budget / 2);
return `${text.slice(0, head)}${text.slice(-tail)}`;
}
function getTruncationStyle(mode: TooltipTruncationMode): string {
if (mode === 'end') {
return TRUNCATION_STYLE;
}
if (mode === 'off') {
return '';
}
// 'start' and 'middle' are already sliced upstream; keep them on one line.
return NOWRAP_STYLE;
}
export function tooltipHtml(
data: string[][],
title?: string,
focusedRow?: number,
truncation: TooltipTruncationMode = 'end',
) {
const truncationStyle = getTruncationStyle(truncation);
const titleRow = title
? `<span style="font-weight: 700;${TRUNCATION_STYLE}">${title}</span>`
? `<span style="font-weight: 700;${truncationStyle}">${title}</span>`
: '';
return sanitizeHtml(`
<div>
@@ -46,7 +98,7 @@ export function tooltipHtml(
const cellStyle = `
text-align: ${j > 0 ? 'right' : 'left'};
padding-left: ${j === 0 ? 0 : 16}px;
${TRUNCATION_STYLE}
${truncationStyle}
`;
return `<td style="${cellStyle}">${cell}</td>`;
});
@@ -16,7 +16,12 @@
* specific language governing permissions and limitations
* under the License.
*/
import { sanitizeHtml, tooltipHtml } from '@superset-ui/core';
import {
sanitizeHtml,
tooltipHtml,
truncateLabel,
TRUNCATION_MAX_CHARS,
} from '@superset-ui/core';
const TITLE_STYLE =
'style="font-weight: 700;max-width:300px;overflow:hidden;text-overflow:ellipsis;"';
@@ -182,3 +187,88 @@ test('should preserve table styling after sanitization (fixes ECharts tooltip fo
expect(html).toContain('padding-left:16px');
expect(html).toContain('max-width:300px');
});
describe('truncateLabel', () => {
const long = 'prod-us-east-1-service-checkout-latency-p99'; // 43 chars
test('returns text unchanged for off and end', () => {
expect(truncateLabel(long, 'off')).toBe(long);
expect(truncateLabel(long, 'end')).toBe(long);
});
test('defaults to end, which does not slice', () => {
expect(truncateLabel(long)).toBe(long);
});
test('truncates the start, keeping the distinguishing suffix', () => {
expect(truncateLabel(long, 'start')).toBe(
'…-us-east-1-service-checkout-latency-p99',
);
expect(truncateLabel(long, 'start')).toHaveLength(TRUNCATION_MAX_CHARS);
});
test('truncates the middle, keeping both ends', () => {
expect(truncateLabel(long, 'middle')).toBe(
'prod-us-east-1-servi…heckout-latency-p99',
);
expect(truncateLabel(long, 'middle')).toHaveLength(TRUNCATION_MAX_CHARS);
});
test('leaves text at or under the limit untouched', () => {
const atLimit = 'x'.repeat(TRUNCATION_MAX_CHARS);
expect(truncateLabel(atLimit, 'start')).toBe(atLimit);
expect(truncateLabel(atLimit, 'middle')).toBe(atLimit);
expect(truncateLabel('short', 'start')).toBe('short');
expect(truncateLabel('', 'middle')).toBe('');
});
test('truncates text one character over the limit', () => {
const overLimit = 'x'.repeat(TRUNCATION_MAX_CHARS + 1);
expect(truncateLabel(overLimit, 'start')).toBe(
`${'x'.repeat(TRUNCATION_MAX_CHARS - 1)}`,
);
});
});
describe('tooltipHtml truncation modes', () => {
const rows = [['label', 'value']];
// sanitizeHtml normalizes spacing inside style attributes, and it does so
// differently across versions, so compare with whitespace stripped.
const styles = (
title: string | undefined,
truncation?: 'off' | 'end' | 'start' | 'middle',
) => removeWhitespaces(tooltipHtml(rows, title, undefined, truncation));
test('emits the 300px cap for end and for the default', () => {
expect(styles('Title', 'end')).toContain('max-width:300px');
expect(tooltipHtml(rows, 'Title')).toBe(
tooltipHtml(rows, 'Title', undefined, 'end'),
);
});
test('emits no truncation style for off', () => {
const html = styles('Title', 'off');
expect(html).not.toContain('max-width');
expect(html).not.toContain('text-overflow');
expect(html).not.toContain('white-space');
});
test.each(['start', 'middle'] as const)(
'emits nowrap instead of a cap for %s',
mode => {
const html = styles('Title', mode);
expect(html).toContain('white-space:nowrap');
expect(html).not.toContain('max-width');
},
);
test('never slices cell text itself, whatever the mode', () => {
const longCell = 'y'.repeat(TRUNCATION_MAX_CHARS + 20);
(['off', 'end', 'start', 'middle'] as const).forEach(mode => {
expect(tooltipHtml([[longCell]], undefined, undefined, mode)).toContain(
longCell,
);
});
});
});
+4
View File
@@ -47,6 +47,10 @@ export default defineConfig({
// Retry logic - 2 retries in CI, 0 locally
retries: process.env.CI ? 2 : 0,
// Disable capturing Git commit info as the project's history is increasingly dense
// and breach Playwright's default 3-seconds `git` command timeout limit
captureGitInfo: { commit: false, diff: false },
// Reporter configuration - multiple reporters for better visibility
reporter: process.env.CI
? [
@@ -30,12 +30,12 @@
},
"dependencies": {
"d3": "^3.5.17",
"prop-types": "^15.8.1",
"react": "^19.2.7"
"prop-types": "^15.8.1"
},
"peerDependencies": {
"@apache-superset/core": "*",
"@superset-ui/chart-controls": "*",
"@superset-ui/core": "*"
"@superset-ui/core": "*",
"react": "^18.3.0"
}
}
@@ -17,6 +17,10 @@
* under the License.
*/
import { getNumberFormatter } from '@superset-ui/core';
import { render, fireEvent } from '../../../../spec/helpers/testing-library';
import BigNumberVis from './BigNumberViz';
/**
* Tests for the color threshold formatter logic in BigNumberViz.
*
@@ -83,3 +87,33 @@ describe('BigNumberViz color formatters', () => {
expect(getColorFromValue).not.toHaveBeenCalled();
});
});
describe('BigNumberViz context menu', () => {
test('invokes onContextMenu and stops the event bubbling to ancestor handlers', () => {
const onContextMenu = jest.fn();
const ancestorHandler = jest.fn();
const { container } = render(
<div onContextMenu={ancestorHandler}>
<BigNumberVis
width={200}
height={100}
bigNumber={42}
headerFormatter={getNumberFormatter()}
headerFontSize={0.3}
subheaderFontSize={0.125}
subtitleFontSize={0.125}
subtitle=""
refs={{}}
onContextMenu={onContextMenu}
/>
</div>,
);
const headerLine = container.querySelector('.header-line');
fireEvent.contextMenu(headerLine!, { clientX: 10, clientY: 20 });
expect(onContextMenu).toHaveBeenCalledWith(10, 20);
expect(ancestorHandler).not.toHaveBeenCalled();
});
});
@@ -224,6 +224,7 @@ function BigNumberVis({
const handleContextMenu = (e: MouseEvent<HTMLDivElement>) => {
if (onContextMenu) {
e.preventDefault();
e.stopPropagation();
onContextMenu(e.nativeEvent.clientX, e.nativeEvent.clientY);
}
};
@@ -390,6 +390,7 @@ export default function transformProps(chartProps: EchartsGanttChartProps) {
[GenericDataType.String]: undefined,
[GenericDataType.Temporal]: tooltipTimeFormatter,
[GenericDataType.Boolean]: undefined,
[GenericDataType.MultiValue]: undefined,
};
const echartOptions: EChartsCoreOption = {
@@ -40,6 +40,7 @@ import {
TimeseriesChartDataResponseResult,
TimeseriesDataRecord,
tooltipHtml,
truncateLabel,
ValueFormatter,
} from '@superset-ui/core';
import { GenericDataType } from '@apache-superset/core/common';
@@ -207,6 +208,7 @@ export default function transformProps(
zoomable,
richTooltip,
tooltipSortByMetric,
tooltipTruncation,
xAxisBounds,
xAxisLabelRotation,
xAxisLabelInterval,
@@ -907,13 +909,19 @@ export default function transformProps(
formatter: primarySeries.has(key)
? tooltipFormatter
: tooltipFormatterSecondary,
truncation: tooltipTruncation,
});
rows.push(row);
if (key === focusedSeries) {
focusedRow = rows.length - 1;
}
});
return tooltipHtml(rows, tooltipFormatter(xValue), focusedRow);
return tooltipHtml(
rows,
truncateLabel(tooltipFormatter(xValue), tooltipTruncation),
focusedRow,
tooltipTruncation,
);
},
},
legend: {
@@ -24,6 +24,7 @@ import {
ContributionType,
TimeFormatter,
AxisType,
TooltipTruncationMode,
} from '@superset-ui/core';
import {
BaseChartProps,
@@ -59,6 +60,7 @@ export type EchartsMixedTimeseriesFormData = QueryFormData & {
timeGrainSqla?: TimeGranularity;
forceMaxInterval?: boolean;
tooltipTimeFormat?: string;
tooltipTruncation?: TooltipTruncationMode;
zoomable: boolean;
richTooltip: boolean;
showQueryIdentifiers?: boolean;
@@ -108,6 +110,7 @@ export const DEFAULT_FORM_DATA: EchartsMixedTimeseriesFormData = {
yAxisFormatSecondary: TIMESERIES_DEFAULTS.yAxisFormat,
yAxisTitleSecondary: DEFAULT_TITLE_FORM_DATA.yAxisTitle,
tooltipTimeFormat: TIMESERIES_DEFAULTS.tooltipTimeFormat,
tooltipTruncation: TIMESERIES_DEFAULTS.tooltipTruncation,
xAxisBounds: TIMESERIES_DEFAULTS.xAxisBounds,
xAxisForceCategorical: TIMESERIES_DEFAULTS.xAxisForceCategorical,
xAxisTimeFormat: TIMESERIES_DEFAULTS.xAxisTimeFormat,
@@ -73,6 +73,7 @@ export const DEFAULT_FORM_DATA: EchartsTimeseriesFormData = {
seriesType: EchartsTimeseriesSeriesType.Line,
stack: false,
tooltipTimeFormat: 'smart_date',
tooltipTruncation: 'end',
xAxisTimeFormat: 'smart_date',
xAxisNumberFormat: 'SMART_NUMBER',
truncateXAxis: true,
@@ -30,6 +30,7 @@ import {
DTTM_ALIAS,
ensureIsArray,
tooltipHtml,
truncateLabel,
getCustomFormatter,
getMetricLabel,
getNumberFormatter,
@@ -303,6 +304,7 @@ export default function transformProps(
tooltipSortByMetric,
showTooltipTotal,
showTooltipPercentage,
tooltipTruncation,
truncateXAxis,
truncateYAxis,
xAxis: xAxisOrig,
@@ -1449,6 +1451,7 @@ export default function transformProps(
seriesName: key,
formatter,
marker,
truncation: tooltipTruncation,
});
const annotationRow = annotationLayers.some(
@@ -1482,7 +1485,12 @@ export default function transformProps(
}
rows.push(totalRow);
}
return tooltipHtml(rows, tooltipFormatter(xValue), focusedRow);
return tooltipHtml(
rows,
truncateLabel(tooltipFormatter(xValue), tooltipTruncation),
focusedRow,
tooltipTruncation,
);
},
},
legend: {
@@ -25,6 +25,7 @@ import {
QueryFormMetric,
TimeFormatter,
TimeGranularity,
TooltipTruncationMode,
} from '@superset-ui/core';
import {
BaseChartProps,
@@ -82,6 +83,7 @@ export type EchartsTimeseriesFormData = QueryFormData & {
tooltipTimeFormat?: string;
showTooltipTotal?: boolean;
showTooltipPercentage?: boolean;
tooltipTruncation?: TooltipTruncationMode;
truncateXAxis: boolean;
truncateYAxis: boolean;
yAxisFormat?: string;
@@ -16,9 +16,13 @@
* specific language governing permissions and limitations
* under the License.
*/
import { render, waitFor } from '../../../../spec/helpers/testing-library';
import type { EChartsCoreOption } from 'echarts/core';
import Echart, { isReportScreenshotMode } from './Echart';
import { render, waitFor } from '../../../../spec/helpers/testing-library';
import Echart, {
ECHARTS_HOST_CLASS,
ECHARTS_RENDER_FINISHED_CLASS,
isReportScreenshotMode,
} from './Echart';
import type { EchartsProps } from '../types';
type Handler = (params: unknown) => void;
@@ -272,3 +276,31 @@ test('keeps animation enabled when not in report screenshot mode', async () => {
const lastOptions = mockChart.setOption.mock.calls.at(-1)?.[0];
expect(lastOptions.animation).not.toBe(false);
});
test('tags the ECharts canvas host with the readiness-gate class', async () => {
const { container } = render(renderEchart(), {
initialState,
useRedux: true,
});
await waitFor(() => expect(mockChart.setOption).toHaveBeenCalled());
expect(container.querySelector(`.${ECHARTS_HOST_CLASS}`)).not.toBeNull();
});
test('marks the host painted only on the ECharts `finished` event', async () => {
const { container } = render(renderEchart(), {
initialState,
useRedux: true,
});
await waitFor(() => expect(mockChart.setOption).toHaveBeenCalled());
const host = container.querySelector(`.${ECHARTS_HOST_CLASS}`) as HTMLElement;
expect(host).not.toBeNull();
// `setOption` ran during mount, which clears the marker; `finished` has not
// fired yet, so the host must NOT be flagged as painted.
expect(host).not.toHaveClass(ECHARTS_RENDER_FINISHED_CLASS);
// Simulate ECharts completing its draw -> the host is flagged painted.
trigger('finished');
expect(host).toHaveClass(ECHARTS_RENDER_FINISHED_CLASS);
});
@@ -138,6 +138,15 @@ export function isReportScreenshotMode(): boolean {
}
}
// Report-screenshot readiness contract (see superset/utils/screenshot_utils.py).
// `echarts-host` marks the canvas host element; `echarts-render-finished` is
// toggled OFF before each setOption and ON in the ECharts `finished` event --
// the only signal that the canvas is fully painted (chartStatus/onRenderSuccess
// both fire pre-paint). The readiness gate treats a host that lacks
// `echarts-render-finished` as not-yet-painted so it never captures a blank chart.
export const ECHARTS_HOST_CLASS = 'echarts-host';
export const ECHARTS_RENDER_FINISHED_CLASS = 'echarts-render-finished';
function Echart(
{
width,
@@ -201,6 +210,11 @@ function Echart(
width,
height,
});
// Paint marker for the report-screenshot readiness gate. `finished`
// is the only event that guarantees the canvas is fully drawn.
chartRef.current.on('finished', () => {
divRef.current?.classList.add(ECHARTS_RENDER_FINISHED_CLASS);
});
}
// did mount
handleSizeChange({ width, height });
@@ -321,6 +335,9 @@ function Echart(
}
)?.dataZoom
: undefined;
// Clear the paint marker before (re)drawing; the `finished` handler
// re-adds it once the new frame is fully rendered.
divRef.current?.classList.remove(ECHARTS_RENDER_FINISHED_CLASS);
chartRef.current?.setOption(themedEchartOptions, {
notMerge,
replaceMerge: notMerge ? undefined : ['series'],
@@ -412,7 +429,14 @@ function Echart(
handleSizeChange({ width, height });
}, [width, height, handleSizeChange]);
return <Styles ref={divRef} height={height} width={width} />;
return (
<Styles
ref={divRef}
className={ECHARTS_HOST_CLASS}
height={height}
width={width}
/>
);
}
export default forwardRef(Echart);
@@ -315,6 +315,27 @@ const tooltipPercentageControl: ControlSetItem = {
},
};
const tooltipTruncationControl: ControlSetItem = {
name: 'tooltipTruncation',
config: {
type: 'SelectControl',
freeForm: false,
label: t('Truncate labels'),
renderTrigger: true,
default: 'end',
clearable: false,
choices: [
['off', t('Off')],
['end', t('End')],
['start', t('Start')],
['middle', t('Middle')],
],
description: t(
'Where to place the ellipsis when a tooltip label is too long. Choose Off to always show the full label, or Start when labels share a common prefix.',
),
},
};
export const richTooltipSection: ControlSetRow[] = [
[<ControlSubSectionHeader>{t('Tooltip')}</ControlSubSectionHeader>],
[richTooltipControl],
@@ -322,6 +343,7 @@ export const richTooltipSection: ControlSetRow[] = [
[tooltipPercentageControl],
[tooltipSortByMetricControl],
[tooltipTimeFormatControl],
[tooltipTruncationControl],
];
const sortSeriesType: ControlSetItem = {
@@ -16,7 +16,13 @@
* specific language governing permissions and limitations
* under the License.
*/
import { DataRecord, DTTM_ALIAS, ValueFormatter } from '@superset-ui/core';
import {
DataRecord,
DTTM_ALIAS,
truncateLabel,
TooltipTruncationMode,
ValueFormatter,
} from '@superset-ui/core';
import type { OptionName, SeriesOption } from 'echarts/types/src/util/types';
import type { TooltipMarker } from 'echarts/types/src/util/format';
import {
@@ -91,12 +97,16 @@ export const formatForecastTooltipSeries = ({
forecastUpper,
marker,
formatter,
truncation = 'end',
}: ForecastValue & {
seriesName: string;
marker: TooltipMarker;
formatter: ValueFormatter;
truncation?: TooltipTruncationMode;
}): string[] => {
const name = `${marker}${sanitizeHtml(seriesName)}`;
// Truncate before sanitizing and before the marker is prepended: slicing a
// string that already contains markup would cut into the marker's tag.
const name = `${marker}${sanitizeHtml(truncateLabel(seriesName, truncation))}`;
let value = typeof observation === 'number' ? formatter(observation) : '';
// Use finite-number checks rather than truthiness so that legitimate
// zero values (e.g. a forecast that crosses zero, or a confidence bound of
@@ -27,6 +27,7 @@ import {
VizType,
ChartDataResponseResult,
TimeGranularity,
TooltipTruncationMode,
} from '@superset-ui/core';
import { GenericDataType } from '@apache-superset/core/common';
import {
@@ -1295,3 +1296,59 @@ test('y-axis title position: non-Left sets nameLocation to end', () => {
expect(yAxis[1].nameGap).toEqual(30);
expect(yAxis[1].nameLocation).toEqual('end');
});
describe('EchartsMixedTimeseries tooltip truncation', () => {
const longSeriesName = 'prod-us-east-1-service-checkout-latency-p99';
const marker = '<span style="background-color:#1f77b4;"></span>';
const buildTooltip = (tooltipTruncation?: TooltipTruncationMode) => {
const chartProps = createEchartsTimeseriesTestChartProps<
EchartsMixedTimeseriesFormData,
EchartsMixedTimeseriesProps
>({
...MIXED_TIMESERIES_CHART_PROPS_DEFAULTS,
defaultQueriesData: queriesData,
formData: {
...formData,
...(tooltipTruncation ? { tooltipTruncation } : {}),
},
queriesData,
});
const { echartOptions } = transformProps(chartProps);
const { formatter } = echartOptions.tooltip as {
formatter: (params: unknown) => string;
};
// richTooltip is false in this fixture, so the trigger is 'item' and the
// formatter receives a single param object rather than an array.
return formatter({
seriesId: longSeriesName,
seriesName: longSeriesName,
value: [599616000000, 1],
marker,
});
};
test('keeps full text with the CSS cap by default', () => {
const html = buildTooltip();
expect(html.replace(/\s/g, '')).toContain('max-width:300px');
expect(html).toContain(longSeriesName);
});
test('removes the cap and keeps full text when off', () => {
const html = buildTooltip('off');
expect(html).not.toContain('max-width');
expect(html).toContain(longSeriesName);
});
test('drops the shared prefix when truncating from the start', () => {
const html = buildTooltip('start');
expect(html).not.toContain('prod-us-east');
expect(html).toContain('latency-p99');
expect(html).toContain('background-color:#1f77b4');
});
test('keeps both ends when truncating the middle', () => {
const html = buildTooltip('middle');
expect(html).toContain('prod-us-east-1-servi…heckout-latency-p99');
expect(html).not.toContain(longSeriesName);
});
});
@@ -32,6 +32,7 @@ import {
TimeseriesAnnotationLayer,
ChartDataResponseResult,
TimeGranularity,
TooltipTruncationMode,
} from '@superset-ui/core';
import { GenericDataType } from '@apache-superset/core/common';
import { supersetTheme } from '@apache-superset/core/theme';
@@ -2437,3 +2438,94 @@ test('honors the snake_case flag the compare-chart migration stores in params',
[BASE_TIMESTAMP + 300000000, 2],
]);
});
describe('EchartsTimeseries tooltip truncation', () => {
const longSeriesName = 'prod-us-east-1-service-checkout-latency-p99';
const marker = '<span style="background-color:#1f77b4;"></span>';
const buildTooltip = (
tooltipTruncation?: TooltipTruncationMode,
xValue: string | number = 599616000000,
) => {
const chartProps = new ChartProps({
formData: {
colorScheme: 'bnbColors',
datasource: '3__table',
granularity_sqla: 'ds',
metric: 'sum__num',
groupby: ['foo'],
viz_type: 'my_viz',
...(tooltipTruncation ? { tooltipTruncation } : {}),
} as SqlaFormData,
width: 800,
height: 600,
queriesData: [
{
data: [
{ [longSeriesName]: 1, __timestamp: 599616000000 },
{ [longSeriesName]: 3, __timestamp: 599916000000 },
],
},
],
theme: supersetTheme,
});
const { echartOptions } = transformProps(
chartProps as EchartsTimeseriesChartProps,
);
const { formatter } = echartOptions.tooltip as {
formatter: (params: unknown) => string;
};
return formatter([
{
seriesId: longSeriesName,
seriesName: longSeriesName,
value: [xValue, 1],
marker,
},
]);
};
test('applies the CSS cap and keeps full text by default', () => {
const html = buildTooltip();
expect(html).toContain(longSeriesName);
// sanitizeHtml normalizes spacing inside style attributes, so compare with
// whitespace stripped rather than hard-coding one version's formatting.
expect(html.replace(/\s/g, '')).toContain('max-width:300px');
});
test('removes the cap and keeps full text when off', () => {
const html = buildTooltip('off');
expect(html).not.toContain('max-width');
expect(html).toContain(longSeriesName);
});
test('drops the shared prefix when truncating from the start', () => {
const html = buildTooltip('start');
expect(html).not.toContain('prod-us-east');
expect(html).toContain('latency-p99');
expect(html.replace(/\s/g, '')).toContain('white-space:nowrap');
});
test('keeps both ends when truncating the middle', () => {
const html = buildTooltip('middle');
expect(html).toContain('prod-us-east-1-servi…heckout-latency-p99');
expect(html).not.toContain(longSeriesName);
});
test('preserves the echarts marker in every mode', () => {
(['off', 'end', 'start', 'middle'] as const).forEach(mode => {
expect(buildTooltip(mode)).toContain('background-color:#1f77b4');
});
});
test('truncates a long non-temporal x-axis title', () => {
const longCategory = 'prod-us-east-1-service-checkout-cohort-2026';
const html = buildTooltip('start', longCategory);
expect(html).not.toContain(longCategory);
expect(html).toContain('cohort-2026');
});
test('leaves a long title alone in the default mode', () => {
const longCategory = 'prod-us-east-1-service-checkout-cohort-2026';
expect(buildTooltip(undefined, longCategory)).toContain(longCategory);
});
});
@@ -16,7 +16,11 @@
* specific language governing permissions and limitations
* under the License.
*/
import { getNumberFormatter, NumberFormats } from '@superset-ui/core';
import {
getNumberFormatter,
NumberFormats,
TRUNCATION_MAX_CHARS,
} from '@superset-ui/core';
import { SeriesOption } from 'echarts';
import {
extractForecastSeriesContext,
@@ -411,3 +415,52 @@ test('formatForecastTooltipSeries should skip non-finite forecast values', () =>
}),
).toEqual(['<img>qwerty', '10']);
});
describe('formatForecastTooltipSeries truncation', () => {
const marker =
'<span style="display:inline-block;width:10px;height:10px;background-color:#1f77b4;"></span>';
const longName = 'prod-us-east-1-service-checkout-latency-p99'; // 43 chars
const intFormatter = getNumberFormatter(NumberFormats.INTEGER);
const format = (truncation?: 'off' | 'end' | 'start' | 'middle') =>
formatForecastTooltipSeries({
seriesName: longName,
observation: 1,
marker,
formatter: intFormatter,
...(truncation ? { truncation } : {}),
})[0];
test('leaves the name intact by default and for off/end', () => {
expect(format()).toContain(longName);
expect(format('off')).toContain(longName);
expect(format('end')).toContain(longName);
});
test('slices the start of the name without harming the marker', () => {
const cell = format('start');
expect(cell).toContain(marker);
expect(cell).toContain('…-us-east-1-service-checkout-latency-p99');
expect(cell).not.toContain('prod-us-east');
});
test('slices the middle of the name without harming the marker', () => {
const cell = format('middle');
expect(cell).toContain(marker);
expect(cell).toContain('prod-us-east-1-servi…heckout-latency-p99');
});
test('measures the budget against the name, not the marker markup', () => {
// The marker alone is far longer than the budget. If truncation were
// applied to the concatenated cell, a short name would be mangled.
expect(marker.length).toBeGreaterThan(TRUNCATION_MAX_CHARS);
const [cell] = formatForecastTooltipSeries({
seriesName: 'cpu',
observation: 1,
marker,
formatter: intFormatter,
truncation: 'start',
});
expect(cell).toBe(`${marker}cpu`);
});
});
@@ -33,7 +33,7 @@
"mapbox-gl": "^3.28.1",
"maplibre-gl": "^5.24.0",
"react-map-gl": "^8.1.2",
"supercluster": "^8.0.1"
"supercluster": "^9.0.0"
},
"peerDependencies": {
"@apache-superset/core": "*",
@@ -164,7 +164,7 @@ export async function selectOption(option: string, selectName?: string) {
const item = await waitFor(() =>
within(
// eslint-disable-next-line testing-library/no-node-access
document.querySelector('.rc-virtual-list')!,
document.querySelector('.ant-select-dropdown-list')!,
).getByText(option),
);
await userEvent.click(item);
@@ -17,6 +17,7 @@
* under the License.
*/
import { useState } from 'react';
import fetchMock from 'fetch-mock';
import {
cleanup,
render,
@@ -35,6 +36,10 @@ import { useDrillDetailMenuItems, DrillDetailMenuItemsProps } from './index';
/* eslint jest/expect-expect: ["warn", { "assertFunctionNames": ["expect*"] }] */
// Opening the context menu logs an event, and an unmatched request makes
// fetch-mock throw inside the component.
fetchMock.post('glob:*/log/?*', {});
jest.mock(
'../DrillDetail/DrillDetailPane',
() =>
@@ -1627,9 +1627,7 @@ function DatasourceEditor({
{t(
'Default URL to redirect to when accessing from the dataset list page. Accepts relative URLs such as',
)}{' '}
<Typography.Text code>
/superset/dashboard/{'{id}'}/
</Typography.Text>
<Typography.Text code>/dashboard/{'{id}'}/</Typography.Text>
</>
}
control={<TextControl controlId="default_endpoint" />}
@@ -71,6 +71,17 @@ test('renders Tabs', async () => {
expect(screen.getByTestId('edit-dataset-tabs')).toBeInTheDocument();
});
test('recommends a registered client route for the default URL', async () => {
await asyncRender(createProps());
userEvent.click(screen.getByRole('tab', { name: 'Settings' }));
expect(await screen.findByText('/dashboard/{id}/')).toBeInTheDocument();
expect(
screen.queryByText('/superset/dashboard/{id}/'),
).not.toBeInTheDocument();
});
test('can sync columns from source', async () => {
const testProps = createProps();
await asyncRender({
+31
View File
@@ -0,0 +1,31 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import {
URL_PARAMS,
RESERVED_CHART_URL_PARAMS,
RESERVED_DASHBOARD_URL_PARAMS,
} from 'src/constants';
test('permalinkKey is reserved on both the chart and dashboard URL param lists', () => {
// Dashboard and explore permalinks resolve against different backend
// KV resources/salts, so a key from one must never leak into the other's
// URL via the reserved-params passthrough logic.
expect(RESERVED_DASHBOARD_URL_PARAMS).toContain(URL_PARAMS.permalinkKey.name);
expect(RESERVED_CHART_URL_PARAMS).toContain(URL_PARAMS.permalinkKey.name);
});
+1
View File
@@ -123,6 +123,7 @@ export const RESERVED_CHART_URL_PARAMS: string[] = [
URL_PARAMS.datasourceId.name,
URL_PARAMS.datasourceType.name,
URL_PARAMS.datasetId.name,
URL_PARAMS.permalinkKey.name,
URL_PARAMS.versionHistory.name,
];
export const RESERVED_DASHBOARD_URL_PARAMS: string[] = [
@@ -468,7 +468,7 @@ function SliceAdder({
<AutoSizer>
{({ height, width }: { height: number; width: number }) => (
<List
style={{ width, height }}
style={{ width, height, maxHeight: height }}
rowCount={filteredSlices.length}
rowHeight={DEFAULT_CELL_HEIGHT}
rowProps={listRowProps}
@@ -16,8 +16,20 @@
* specific language governing permissions and limitations
* under the License.
*/
import {
ChartCustomizationType,
type ChartCustomization,
} from '@superset-ui/core';
import { LabeledValue } from '@superset-ui/core/components';
import { createLabelSortComparator } from './GroupByFilterCard';
import { render, screen } from 'spec/helpers/testing-library';
import GroupByFilterCard, {
createLabelSortComparator,
} from './GroupByFilterCard';
jest.mock('src/utils/cachedSupersetGet', () => ({
// Never resolves, pinning the card in its column-loading state.
cachedSupersetGet: jest.fn(() => new Promise(() => {})),
}));
const apple: LabeledValue = { value: 'a', label: 'Apple' };
const banana: LabeledValue = { value: 'b', label: 'Banana' };
@@ -39,3 +51,27 @@ test('preserves source order when sortAscending is unset', () => {
expect(compare(apple, banana)).toBe(0);
expect(compare(banana, apple)).toBe(0);
});
const groupByCustomization: ChartCustomization = {
id: 'groupby-1',
name: 'Group By',
filterType: 'filter_groupby',
type: ChartCustomizationType.ChartCustomization,
targets: [{ datasetId: 1 }],
scope: { rootPath: [], excluded: [] },
controlValues: {},
defaultDataMask: {},
};
test('renders the column-loading spinner small and muted', async () => {
render(<GroupByFilterCard customizationItem={groupByCustomization} />, {
useRedux: true,
initialState: {
dataMask: {},
nativeFilters: { filters: {} },
},
});
const spinner = await screen.findByTestId('loading-indicator');
expect(spinner).toHaveClass('inline');
expect(spinner).toHaveStyle({ opacity: 0.25, width: '40px' });
});
@@ -645,7 +645,7 @@ const GroupByFilterCard: FC<GroupByFilterCardProps> = ({
{loading && (
<div style={{ textAlign: 'center', marginTop: 8 }}>
<Loading position="inline" />
<Loading position="inline" size="s" muted />
</div>
)}
</div>
@@ -76,7 +76,7 @@ const typeIntoSelect = async (text: string) => {
const findOption = (text: string) =>
waitFor(() => {
// eslint-disable-next-line testing-library/no-node-access
const virtualList = document.querySelector('.rc-virtual-list');
const virtualList = document.querySelector('.ant-select-dropdown-list');
if (!virtualList) {
throw new Error('Virtual list not found');
}
@@ -72,3 +72,13 @@ test('omits datasourceType when undefined', () => {
});
expect(target).not.toHaveProperty('datasourceType');
});
test('omits datasourceType when there is no dataset', () => {
// The modal stamps a hidden ``datasourceType`` field on every filter form,
// including dataset-less types. Without a dataset there is nothing for it to
// describe, and emitting it would diverge from the ``{}`` target the import
// and seed paths write.
expect(
buildNativeFilterTarget({ datasourceType: DatasourceType.Table }),
).toEqual({});
});
@@ -33,9 +33,9 @@ export interface TargetFormInputs {
* Build the ``NativeFilterTarget`` carried by a native filter or chart
* customization from its form inputs.
*
* Consolidates what used to live in three places ``filterTransformer``,
* ``customizationTransformer``, and ``createHandleSave`` so changes to the
* target shape only need to happen here.
* Consolidates what used to live in ``filterTransformer`` and
* ``customizationTransformer`` so changes to the target shape only need to
* happen here.
*/
export function buildNativeFilterTarget(
formInputs: TargetFormInputs,
@@ -49,7 +49,11 @@ export function buildNativeFilterTarget(
: formInputs.dataset;
}
if (formInputs.datasourceType) {
// ``datasourceType`` describes the selected dataset, so it only belongs on a
// target that has one. Emitting it for a dataset-less filter (e.g.
// ``filter_time``) would make a UI save serialize a target the import and
// seed paths write as ``{}``.
if (formInputs.dataset != null && formInputs.datasourceType) {
target.datasourceType = formInputs.datasourceType;
}
@@ -0,0 +1,102 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import { ChartCustomization, ChartCustomizationType } from '@superset-ui/core';
import { ChartCustomizationsFormItem } from '../types';
import { transformCustomizationForSave } from './customizationTransformer';
const baseFormItem = {
type: ChartCustomizationType.ChartCustomization,
scope: { rootPath: ['ROOT_ID'], excluded: [] },
controlValues: {},
requiredFirst: {},
defaultValue: null,
defaultDataMask: { filterState: {}, extraFormData: {} },
sortMetric: null,
description: '',
// form-only field that must never leak into the saved customization
defaultValueQueriesData: null,
} as unknown as ChartCustomizationsFormItem;
test('serializes a dataset-less customization into a full ChartCustomization', () => {
// Customization plugins declaring ``datasourceCount: 0`` render no dataset
// control, so their form item carries neither ``dataset`` nor ``targets``.
const formItem = {
...baseFormItem,
name: 'Layer visibility',
filterType: 'customization_deckgl_layer_visibility',
} as unknown as ChartCustomizationsFormItem;
const result = transformCustomizationForSave(
'CHART_CUSTOMIZATION-abc',
formItem,
) as ChartCustomization;
expect(result.targets).toEqual([{}]);
expect(result.defaultDataMask).toBeDefined();
expect(result.removed).toBe(false);
expect(result).not.toHaveProperty('defaultValueQueriesData');
});
test('serializes a dataset-backed customization into a full ChartCustomization', () => {
const formItem = {
...baseFormItem,
name: 'Group by',
filterType: 'customization_dynamic_group_by',
dataset: { value: 42, label: 'sales' },
column: 'region',
} as unknown as ChartCustomizationsFormItem;
const result = transformCustomizationForSave(
'CHART_CUSTOMIZATION-def',
formItem,
) as ChartCustomization;
expect(result.targets).toEqual([
{ datasetId: 42, column: { name: 'region' } },
]);
expect(result).not.toHaveProperty('defaultValueQueriesData');
});
test('passes an already-saved ChartCustomization through untouched', () => {
const saved: ChartCustomization = {
id: 'CHART_CUSTOMIZATION-ghi',
name: 'Group by',
filterType: 'customization_dynamic_group_by',
type: ChartCustomizationType.ChartCustomization,
targets: [{ datasetId: 42, column: { name: 'region' } }],
defaultDataMask: { filterState: {}, extraFormData: {} },
controlValues: {},
scope: { rootPath: ['ROOT_ID'], excluded: [] },
description: ' needs trim ',
chartsInScope: [1, 2],
tabsInScope: ['TAB-1'],
};
const result = transformCustomizationForSave(
'CHART_CUSTOMIZATION-ghi',
saved,
) as ChartCustomization;
expect(result.targets).toEqual([
{ datasetId: 42, column: { name: 'region' } },
]);
expect(result.chartsInScope).toEqual([1, 2]);
expect(result.tabsInScope).toEqual(['TAB-1']);
expect(result.description).toBe('needs trim');
});
@@ -69,7 +69,10 @@ function isDividerType(
function isFormInput(
formInputs: ChartCustomizationFormOrSaved,
): formInputs is ChartCustomizationsFormItem {
return 'dataset' in formInputs && typeof formInputs.dataset === 'object';
// Mirrors `filterTransformer`: a saved customization always carries a
// serialized `targets` array, and dataset-less types (e.g. the deck.gl layer
// visibility customization) have no `dataset` to discriminate on.
return !('targets' in formInputs);
}
function transformCustomizationDivider(
@@ -0,0 +1,156 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import { DatasourceType, Filter, NativeFilterType } from '@superset-ui/core';
import { NativeFiltersFormItem } from '../types';
import { transformFilterForSave } from './filterTransformer';
const baseFormItem = {
type: NativeFilterType.NativeFilter,
scope: { rootPath: ['ROOT_ID'], excluded: [] },
controlValues: {},
requiredFirst: {},
defaultValue: null,
defaultDataMask: { filterState: {}, extraFormData: {} },
description: '',
// form-only fields that must never leak into the saved filter
defaultValueQueriesData: null,
} as unknown as NativeFiltersFormItem;
test('serializes a dataset-less filter (filter_time) into a full Filter', () => {
// A ``filter_time`` filter has no dataset/column controls, so its form item
// carries neither a ``dataset`` nor a ``targets`` key. It must still be
// transformed like any other native filter rather than persisted verbatim.
const formItem: NativeFiltersFormItem = {
...baseFormItem,
name: 'Time Range',
filterType: 'filter_time',
dependencies: ['NATIVE_FILTER-parent'],
// the modal stamps this on every filter form, dataset or not
datasourceType: DatasourceType.Table,
};
const result = transformFilterForSave(
'NATIVE_FILTER-abc',
formItem,
) as Filter;
// Keys the bug used to strip are present and well-formed. The target matches
// the ``{}`` the import and seed paths write, so one logical filter has one
// serialization regardless of provenance.
expect(result.targets).toEqual([{}]);
expect(result.defaultDataMask).toBeDefined();
expect(result.cascadeParentIds).toEqual(['NATIVE_FILTER-parent']);
// Form-only keys must not leak into the persisted config.
expect(result).not.toHaveProperty('defaultValueQueriesData');
expect(result).not.toHaveProperty('dependencies');
// Empty requiredFirst collapses to undefined instead of the raw form object.
expect(result.requiredFirst).toBeUndefined();
// A dataset-less filter has no sort metric control, so the persisted document
// must not gain a ``sortMetric`` key it never had. Asserted on the serialized
// form because ``undefined`` values survive in the object but not in JSON.
expect(JSON.parse(JSON.stringify(result))).not.toHaveProperty('sortMetric');
expect(result.name).toBe('Time Range');
expect(result.filterType).toBe('filter_time');
});
test('serializes a dataset-backed filter (filter_select) into a full Filter', () => {
const formItem: NativeFiltersFormItem = {
...baseFormItem,
name: 'Region',
filterType: 'filter_select',
dataset: { value: 42, label: 'sales' },
column: 'region',
dependencies: [],
};
const result = transformFilterForSave(
'NATIVE_FILTER-def',
formItem,
) as Filter;
expect(result.targets).toEqual([
{ datasetId: 42, column: { name: 'region' } },
]);
expect(result.defaultDataMask).toBeDefined();
expect(result.cascadeParentIds).toEqual([]);
expect(result).not.toHaveProperty('defaultValueQueriesData');
});
test('passes an already-saved Filter through untouched (aside from trimming)', () => {
// Values coming from the stored filter config map (e.g. cascade-parent
// cleanup) already carry a ``targets`` array and must be preserved as-is.
const savedFilter: Filter = {
id: 'NATIVE_FILTER-ghi',
name: 'Time Range',
filterType: 'filter_time',
type: NativeFilterType.NativeFilter,
targets: [{}],
defaultDataMask: { filterState: {}, extraFormData: {} },
cascadeParentIds: ['NATIVE_FILTER-parent'],
controlValues: {},
scope: { rootPath: ['ROOT_ID'], excluded: [] },
description: ' needs trim ',
chartsInScope: [1, 2],
tabsInScope: ['TAB-1'],
};
const result = transformFilterForSave(
'NATIVE_FILTER-ghi',
savedFilter,
) as Filter;
expect(result.targets).toEqual([{}]);
expect(result.cascadeParentIds).toEqual(['NATIVE_FILTER-parent']);
expect(result.chartsInScope).toEqual([1, 2]);
expect(result.tabsInScope).toEqual(['TAB-1']);
expect(result.description).toBe('needs trim');
});
test('rebuilds a saved filter whose targets were already stripped', () => {
// Dashboards affected by this bug hold ``filter_time`` entries with no
// ``targets``. They no longer match the saved-filter branch, so they take the
// form-item path and are repaired on the next save. ``cascadeParentIds`` is
// read from the form's ``dependencies``, which such an entry does not carry —
// the same write that stripped ``targets`` stripped ``cascadeParentIds`` too.
const strippedFilter = {
id: 'NATIVE_FILTER-jkl',
name: 'Time Range',
filterType: 'filter_time',
type: NativeFilterType.NativeFilter,
scope: { rootPath: ['ROOT_ID'], excluded: [] },
controlValues: { timeShift: false },
description: '',
requiredFirst: { 'NATIVE_FILTER-jkl': true },
defaultValueQueriesData: null,
} as unknown as NativeFiltersFormItem;
const result = transformFilterForSave(
'NATIVE_FILTER-jkl',
strippedFilter,
) as Filter;
expect(result.targets).toEqual([{}]);
expect(result.defaultDataMask).toBeDefined();
expect(result.requiredFirst).toBe(true);
expect(result.cascadeParentIds).toEqual([]);
expect(result).not.toHaveProperty('defaultValueQueriesData');
});
@@ -67,7 +67,10 @@ function isDividerType(
function isFormInput(
formInputs: NativeFilterFormOrSaved,
): formInputs is NativeFiltersFormItem {
return 'dataset' in formInputs;
// A saved filter always carries a serialized `targets` array; a form item
// never does. Keying this off `dataset` misclassified filter types with no
// dataset control (e.g. `filter_time`) as already saved.
return !('targets' in formInputs);
}
function transformDivider(
@@ -115,7 +118,7 @@ function transformFormInput(
adhoc_filters: formInputs.adhoc_filters,
time_range: formInputs.time_range,
granularity_sqla: formInputs.granularity_sqla,
sortMetric: formInputs.sortMetric ?? null,
sortMetric: formInputs.sortMetric,
requiredFirst: formInputs.requiredFirst
? Object.values(formInputs.requiredFirst).find(rf => rf)
: undefined,
@@ -18,21 +18,15 @@
*/
import type { FormInstance } from '@superset-ui/core/components';
import { nanoid } from 'nanoid';
import { getInitialDataMask } from 'src/dataMask/reducer';
import {
FilterConfiguration,
NativeFilterType,
NativeFilterTarget,
Filter,
Divider,
ChartCustomizationType,
ChartCustomizationConfiguration,
ChartCustomization,
ChartCustomizationDivider,
} from '@superset-ui/core';
import { logging } from '@apache-superset/core/utils';
import { DASHBOARD_ROOT_ID } from 'src/dashboard/util/constants';
import { buildNativeFilterTarget } from './transformers/buildTarget';
import {
ChartCustomizationsForm,
FilterChangesType,
@@ -101,70 +95,6 @@ export const validateForm = async (
}
};
export const createHandleSave =
(
saveForm: Function,
filterChanges: FilterChangesType,
values: NativeFiltersForm,
filterConfigMap: Record<string, Filter | Divider>,
) =>
async () => {
const transformFilter = (id: string) => {
const formInputs = values.filters?.[id] || filterConfigMap[id];
if (!formInputs) {
return undefined;
}
if (formInputs.type === NativeFilterType.Divider) {
return {
id,
type: NativeFilterType.Divider,
scope: {
rootPath: [DASHBOARD_ROOT_ID],
excluded: [],
},
title: formInputs.title,
description: formInputs.description,
};
}
const target: Partial<NativeFilterTarget> =
buildNativeFilterTarget(formInputs);
return {
id,
adhoc_filters: formInputs.adhoc_filters,
time_range: formInputs.time_range,
controlValues: formInputs.controlValues ?? {},
granularity_sqla: formInputs.granularity_sqla,
...(formInputs.time_grains?.length
? { time_grains: formInputs.time_grains }
: {}),
requiredFirst: Object.values(formInputs.requiredFirst ?? {}).find(
rf => rf,
),
name: formInputs.name,
filterType: formInputs.filterType,
targets: [target],
defaultDataMask: formInputs.defaultDataMask ?? getInitialDataMask(),
cascadeParentIds: formInputs.dependencies || [],
scope: formInputs.scope,
sortMetric: formInputs.sortMetric,
type: formInputs.type,
description: (formInputs.description || '').trim(),
};
};
const transformedModified = filterChanges.modified
.map(transformFilter)
.filter(Boolean);
const newFilterChanges = {
...filterChanges,
modified: transformedModified,
};
await saveForm(newFilterChanges);
};
export const createHandleRemoveItem =
(
setRemovedFilters: (
@@ -148,7 +148,7 @@ export const DatasourceItems = ({
return (
<List
style={{ width: width - BORDER_WIDTH, height }}
style={{ width: width - BORDER_WIDTH, height, maxHeight: height }}
rowHeight={rowHeight}
rowCount={flattenedItems.length}
rowProps={rowProps}
@@ -251,4 +251,11 @@ export const DEFAULT_CONFIG_FORM_LAYOUT: ColumnConfigFormLayout = {
{ name: 'horizontalAlign', override: { defaultValue: 'left' } },
],
],
[GenericDataType.MultiValue]: [
[
'columnWidth',
{ name: 'horizontalAlign', override: { defaultValue: 'left' } },
],
['truncateLongCells'],
],
};
@@ -214,7 +214,9 @@ test('Should filter simple columns by column_name and verbose_name', async () =>
await userEvent.type(combobox, 'revenue');
let dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
let dropdown = document.querySelector(
'.ant-select-dropdown-list',
) as HTMLElement;
expect(within(dropdown).getByText('Total Sales')).toBeInTheDocument();
expect(
within(dropdown).queryByText('User Identifier'),
@@ -226,7 +228,7 @@ test('Should filter simple columns by column_name and verbose_name', async () =>
await userEvent.clear(combobox);
await userEvent.type(combobox, 'Identifier');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('User Identifier')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Sales')).not.toBeInTheDocument();
expect(within(dropdown).queryByText('Creation Date')).not.toBeInTheDocument();
@@ -234,7 +236,7 @@ test('Should filter simple columns by column_name and verbose_name', async () =>
await userEvent.clear(combobox);
await userEvent.type(combobox, '_at');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Creation Date')).toBeInTheDocument();
expect(within(dropdown).getByText('Last Update')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Sales')).not.toBeInTheDocument();
@@ -288,7 +290,9 @@ test('Should filter saved expressions by column_name and verbose_name', async ()
await userEvent.type(combobox, 'revenue');
let dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
let dropdown = document.querySelector(
'.ant-select-dropdown-list',
) as HTMLElement;
expect(within(dropdown).getByText('Total Sales')).toBeInTheDocument();
expect(within(dropdown).queryByText('Tax Amount')).not.toBeInTheDocument();
expect(within(dropdown).queryByText('Net Profit')).not.toBeInTheDocument();
@@ -298,7 +302,7 @@ test('Should filter saved expressions by column_name and verbose_name', async ()
await userEvent.clear(combobox);
await userEvent.type(combobox, 'Rate');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Discount Rate')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Sales')).not.toBeInTheDocument();
expect(within(dropdown).queryByText('Tax Amount')).not.toBeInTheDocument();
@@ -306,7 +310,7 @@ test('Should filter saved expressions by column_name and verbose_name', async ()
await userEvent.clear(combobox);
await userEvent.type(combobox, 'profit');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Net Profit')).toBeInTheDocument();
expect(within(dropdown).getByText('Profit Margin')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Sales')).not.toBeInTheDocument();
@@ -270,6 +270,74 @@ describe('AdhocFilter', () => {
});
expect(adhocFilter.comparator).toBe(undefined);
});
// Charts saved before #32701 persisted `==` as the operation for IS_TRUE and
// IS_FALSE, alongside a boolean comparator. `translateToSql` and the backend
// both key off `operator`, so dropping the comparator would render such a
// filter as `col =` and query it as `col IS NULL`.
test('keeps the legacy boolean comparator for IS_TRUE', () => {
const adhocFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'col',
operator: '==',
operatorId: Operators.IsTrue,
comparator: true,
clause: Clauses.Where,
});
expect(adhocFilter.operator).toBe('==');
expect(adhocFilter.comparator).toBe(true);
expect(adhocFilter.translateToSql()).toBe("col = 'TRUE'");
});
test('keeps the legacy boolean comparator for IS_FALSE', () => {
const adhocFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'col',
operator: '==',
operatorId: Operators.IsFalse,
comparator: false,
clause: Clauses.Where,
});
expect(adhocFilter.operator).toBe('==');
expect(adhocFilter.comparator).toBe(false);
expect(adhocFilter.translateToSql()).toBe("col = 'FALSE'");
});
test('restores the boolean even when the stored comparator is missing', () => {
const adhocFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'col',
operator: '==',
operatorId: Operators.IsTrue,
clause: Clauses.Where,
});
expect(adhocFilter.comparator).toBe(true);
});
test('keeps a legacy boolean filter intact when the control re-posts it', () => {
const stored = {
expressionType: ExpressionTypes.Simple,
subject: 'col',
operator: '==',
operatorId: Operators.IsTrue,
comparator: true,
clause: Clauses.Where,
};
// DndFilterSelect wraps props.value and hands those instances to onChange
const posted = JSON.parse(JSON.stringify(new AdhocFilter(stored)));
expect(posted.operator).toBe('==');
expect(posted.comparator).toBe(true);
expect(posted.operatorId).toBe(Operators.IsTrue);
});
test('leaves a genuine equality filter on a boolean value alone', () => {
const adhocFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'col',
operator: '==',
operatorId: Operators.Equals,
comparator: true,
clause: Clauses.Where,
});
expect(adhocFilter.operator).toBe('==');
expect(adhocFilter.comparator).toBe(true);
expect(adhocFilter.translateToSql()).toBe("col = 'TRUE'");
});
test('sets the label properly if subject is a string', () => {
const adhocFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
@@ -30,6 +30,15 @@ const CUSTOM_OPERATIONS = [...CUSTOM_OPERATORS].map(
op => OPERATOR_ENUM_TO_OPERATOR_TYPE[op].operation,
);
// Charts saved before #32701 store `==` for IS_TRUE/IS_FALSE with the boolean
// in the comparator; blanking it makes them query `col IS NULL`. Restoring it
// leaves the emitted SQL untouched -- reconciling `operator` to `IS TRUE`
// would not, and Druid rejects that predicate on VARCHAR columns.
const LEGACY_BOOLEAN_COMPARATORS = new Map<string, boolean>([
[Operators.IsTrue, true],
[Operators.IsFalse, false],
]);
interface AdhocFilterInput {
expressionType?: string;
subject?: string | { column_name?: string; [key: string]: unknown } | null;
@@ -77,6 +86,16 @@ export default class AdhocFilter {
) {
this.comparator = undefined;
}
if (
this.operator ===
OPERATOR_ENUM_TO_OPERATOR_TYPE[Operators.Equals].operation &&
adhocFilter.operatorId &&
LEGACY_BOOLEAN_COMPARATORS.has(adhocFilter.operatorId)
) {
this.comparator = LEGACY_BOOLEAN_COMPARATORS.get(
adhocFilter.operatorId,
);
}
this.clause = adhocFilter.clause || Clauses.Where;
this.sqlExpression = null;
} else if (this.expressionType === ExpressionTypes.Sql) {
@@ -367,8 +367,22 @@ function AdhocFilterEditPopover({
</ErrorBoundary>
),
},
...(datasource?.type === 'semantic_view'
? []
...(datasource?.type === 'semantic_view' ||
[
Operators.ContainsAny,
Operators.ContainsAll,
Operators.IsEmpty,
Operators.IsNotEmpty,
Operators.LengthEquals,
Operators.LengthGreaterThan,
Operators.LengthLessThan,
Operators.LengthGreaterThanOrEqual,
Operators.LengthLessThanOrEqual,
].includes(adhocFilter.operatorId as Operators)
? // Hide the Custom SQL tab for element-level array operators: they
// have no portable SQL representation, and converting one would
// silently turn the filter into invalid raw SQL.
[]
: [
{
key: ExpressionTypes.Sql,
@@ -35,6 +35,7 @@ import {
} from 'src/explore/constants';
import AdhocMetric from 'src/explore/components/controls/MetricControl/AdhocMetric';
import { FeatureFlag, isFeatureEnabled } from '@superset-ui/core';
import { GenericDataType } from '@apache-superset/core/common';
import fetchMock from 'fetch-mock';
import { TestDataset, Dataset } from '@superset-ui/chart-controls';
@@ -252,6 +253,78 @@ test('shows boolean only operators when subject is number', () => {
].map(operator => expect(isOperatorRelevant(operator, 'value')).toBe(true));
});
test('shows array operators (tier 1 + tier 2) when subject is multi-value', () => {
const props = setup({
adhocFilter: new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'skills',
operatorId: undefined,
operator: undefined,
comparator: undefined,
clause: undefined,
}),
datasource: {
columns: [
{
id: 3,
column_name: 'skills',
type: 'Array(String)',
type_generic: GenericDataType.MultiValue,
},
],
},
});
const { isOperatorRelevant } = useSimpleTabFilterProps(
props as unknown as Props,
);
// Tier 1 (whole-array) + Tier 2 (element-level) are all relevant.
[
Operators.Equals,
Operators.NotEquals,
Operators.In,
Operators.NotIn,
Operators.IsNull,
Operators.IsNotNull,
Operators.ContainsAny,
Operators.ContainsAll,
Operators.IsEmpty,
Operators.IsNotEmpty,
].forEach(operator =>
expect(isOperatorRelevant(operator, 'skills')).toBe(true),
);
// scalar-only operators are hidden for array columns
[Operators.GreaterThan, Operators.LessThan, Operators.Like].forEach(
operator => expect(isOperatorRelevant(operator, 'skills')).toBe(false),
);
});
test('hides element-level array operators for non multi-value columns', () => {
const props = setup({
adhocFilter: new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'value',
operatorId: undefined,
operator: undefined,
comparator: undefined,
clause: undefined,
}),
datasource: {
columns: [{ id: 3, column_name: 'value', type: 'STRING' }],
},
});
const { isOperatorRelevant } = useSimpleTabFilterProps(
props as unknown as Props,
);
[
Operators.ContainsAny,
Operators.ContainsAll,
Operators.IsEmpty,
Operators.IsNotEmpty,
].forEach(operator =>
expect(isOperatorRelevant(operator, 'value')).toBe(false),
);
});
test('will convert from individual comparator to array if the operator changes to multi', () => {
const props = setup();
const { onOperatorChange } = useSimpleTabFilterProps(
@@ -309,6 +382,49 @@ test('will convert from array to individual comparators if the operator changes
);
});
test('resets the comparator when switching between array value families', () => {
// Equal to (whole-array literal) -> Contains all (individual elements):
// the value spaces are incompatible, so the stale value must be cleared.
const wholeArrayFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'scores',
operatorId: Operators.Equals,
operator: OPERATOR_ENUM_TO_OPERATOR_TYPE[Operators.Equals].operation,
comparator: '[5,6,7]',
clause: Clauses.Where,
});
const props = setup({ adhocFilter: wholeArrayFilter });
const { onOperatorChange } = useSimpleTabFilterProps(
props as unknown as Props,
);
onOperatorChange(Operators.ContainsAll);
const lastCall =
props.onChange.mock.calls[props.onChange.mock.calls.length - 1][0];
expect(lastCall.operatorId).toEqual(Operators.ContainsAll);
expect(lastCall.comparator).toBeUndefined();
});
test('keeps the value when switching within the element family', () => {
// Contains any <-> Contains all both take individual elements, so the
// selected elements should carry over.
const elementFilter = new AdhocFilter({
expressionType: ExpressionTypes.Simple,
subject: 'scores',
operatorId: Operators.ContainsAny,
operator: OPERATOR_ENUM_TO_OPERATOR_TYPE[Operators.ContainsAny].operation,
comparator: ['5', '6'],
clause: Clauses.Where,
});
const props = setup({ adhocFilter: elementFilter });
const { onOperatorChange } = useSimpleTabFilterProps(
props as unknown as Props,
);
onOperatorChange(Operators.ContainsAll);
const lastCall =
props.onChange.mock.calls[props.onChange.mock.calls.length - 1][0];
expect(lastCall.comparator).toEqual(['5', '6']);
});
test('passes the new adhocFilter to onChange after onComparatorChange', () => {
const props = setup();
const { onComparatorChange } = useSimpleTabFilterProps(
@@ -399,6 +515,28 @@ test('will not display boolean operators when column type is string', () => {
});
});
test.each(['STRING', 'DATE'])(
'will not display boolean operators when an expression column declares type %s',
type => {
const props = setup({
datasource: {
type: 'table' as const,
datasource_name: 'table1',
schema: 'schema',
columns: [{ column_name: 'value', type, expression: '"value"' }],
},
adhocFilter: simpleAdhocFilter,
});
const { isOperatorRelevant } = useSimpleTabFilterProps(
props as unknown as Props,
);
const booleanOnlyOperators = [Operators.IsTrue, Operators.IsFalse];
booleanOnlyOperators.forEach(operator => {
expect(isOperatorRelevant(operator, 'value')).toBe(false);
});
},
);
test('will display boolean operators when column is an expression', () => {
const props = setup({
datasource: {
@@ -32,6 +32,7 @@ import {
isDefined,
SupersetClient,
} from '@superset-ui/core';
import { GenericDataType } from '@apache-superset/core/common';
import { styled, useTheme, css } from '@apache-superset/core/theme';
import {
Operators,
@@ -118,6 +119,8 @@ export const useSimpleTabFilterProps = (props: Props) => {
const isColumnNumber =
!!column && (column.type === 'INT' || column.type === 'INTEGER');
const isColumnFunction = !!column && !!column.expression;
const isColumnMultiValue =
!!column && column.type_generic === GenericDataType.MultiValue;
if (operator && operator === Operators.LatestPartition) {
const { partitionColumn } = props;
@@ -127,8 +130,41 @@ export const useSimpleTabFilterProps = (props: Props) => {
// hide the TEMPORAL_RANGE operator
return false;
}
// Element-level array operators only apply to multi-value columns.
const arrayElementOperators = [
Operators.ContainsAny,
Operators.ContainsAll,
Operators.IsEmpty,
Operators.IsNotEmpty,
Operators.LengthEquals,
Operators.LengthGreaterThan,
Operators.LengthLessThan,
Operators.LengthGreaterThanOrEqual,
Operators.LengthLessThanOrEqual,
];
if (arrayElementOperators.includes(operator)) {
return isColumnMultiValue;
}
if (isColumnMultiValue) {
// Array columns support whole-array operators (=, !=, In, Not in, null
// checks) plus the element-level operators above. Scalar-only operators
// (Like, <, >, <=, >=) are hidden because they aren't valid on an array.
return [
Operators.Equals,
Operators.NotEquals,
Operators.In,
Operators.NotIn,
Operators.IsNull,
Operators.IsNotNull,
...arrayElementOperators,
].includes(operator);
}
if (operator === Operators.IsTrue || operator === Operators.IsFalse) {
return isColumnBoolean || isColumnNumber || isColumnFunction;
// An expression column may evaluate to a boolean, but that is only a
// safe assumption while its type is unknown; a declared type wins.
return (
isColumnBoolean || isColumnNumber || (isColumnFunction && !column?.type)
);
}
if (isColumnBoolean) {
return operator === Operators.IsNull || operator === Operators.IsNotNull;
@@ -167,9 +203,19 @@ export const useSimpleTabFilterProps = (props: Props) => {
].operation
: null;
if (!isDefined(operator)) {
// if operator is `null`, use the `IN` and reset the comparator.
operator = Operators.In;
operatorId = Operators.In;
// The previous operator is not relevant for the new subject; pick a
// sensible default and reset the comparator. Multi-value (array) columns
// default to "Contains any" (element membership) rather than the
// scalar-only IN.
const newColumn = props.datasource.columns?.find(
col => col.column_name === subject,
);
const defaultOperator =
newColumn?.type_generic === GenericDataType.MultiValue
? Operators.ContainsAny
: Operators.In;
operator = defaultOperator;
operatorId = defaultOperator;
comparator = undefined;
}
@@ -193,10 +239,38 @@ export const useSimpleTabFilterProps = (props: Props) => {
};
const onOperatorChange = (operatorId: Operators) => {
const currentComparator = props.adhocFilter.comparator;
// The value space differs between operator families: element-level array
// ops (Contains any/all) take individual elements, whole-array/scalar ops
// (=, In, …) take whole arrays or scalars, Length ops take a count, and the
// unary ops take nothing. A value from one family is meaningless in another,
// so reset the value when the family changes (e.g. Equal to -> Contains all).
const comparatorKind = (op?: Operators): string => {
if (!op) return 'none';
if (op === Operators.ContainsAny || op === Operators.ContainsAll) {
return 'element';
}
if (
op === Operators.LengthEquals ||
op === Operators.LengthGreaterThan ||
op === Operators.LengthLessThan ||
op === Operators.LengthGreaterThanOrEqual ||
op === Operators.LengthLessThanOrEqual
) {
return 'length';
}
if (DISABLE_INPUT_OPERATORS.includes(op)) return 'none';
return 'value';
};
const valueFamilyChanged =
comparatorKind(props.adhocFilter.operatorId as Operators | undefined) !==
comparatorKind(operatorId);
let newComparator;
// convert between list of comparators and individual comparators
// (e.g. `in ('North America', 'Africa')` to `== 'North America'`)
if (MULTI_OPERATORS.has(operatorId)) {
if (valueFamilyChanged) {
newComparator = undefined;
} else if (MULTI_OPERATORS.has(operatorId)) {
// convert between list of comparators and individual comparators
// (e.g. `in ('North America', 'Africa')` to `== 'North America'`)
newComparator = Array.isArray(currentComparator)
? currentComparator
: [currentComparator].filter(element => element != null);
@@ -433,19 +507,42 @@ const AdhocFilterEditPopoverSimpleTabContent: FC<Props> = props => {
if (loadingComparatorSuggestions) {
controller.abort();
}
// Element-level array operators (Contains any / Contains all) search
// inside the array, so suggest individual elements; whole-array
// operators (=, In, …) keep the default distinct-array suggestions.
const { operatorId } = props.adhocFilter;
const arrayElements =
operatorId === Operators.ContainsAny ||
operatorId === Operators.ContainsAll;
setLoadingComparatorSuggestions(true);
SupersetClient.get({
signal,
endpoint: `/api/v1/datasource/${datasource.type}/${datasource.id}/column/${col}/values/`,
endpoint: `/api/v1/datasource/${datasource.type}/${datasource.id}/column/${col}/values/${
arrayElements ? '?array_elements=true' : ''
}`,
})
.then(({ json }) => {
setSuggestions(
json.result.map(
(suggestion: null | number | boolean | string) => ({
value: suggestion,
label: optionLabel(suggestion),
}),
),
json.result.map((suggestion: unknown) => {
// Complex column values arrive as JS arrays or objects: whole
// arrays for MULTI_VALUE columns (e.g. [5, 6, 7]) and Map/Tuple
// objects for nested-container columns (e.g. {"a": ["x","y"]}).
// A raw array/object is neither a valid single-select value
// (antd collapses an array to its first element) nor renderable
// as a React child (an object throws). Render it as its literal
// string, which is also exactly what the backend's
// parse_array_literal expects for the whole-array operators.
if (suggestion !== null && typeof suggestion === 'object') {
const literal = JSON.stringify(suggestion);
return { value: literal, label: literal };
}
return {
value: suggestion as null | number | boolean | string,
label: optionLabel(
suggestion as null | number | boolean | string,
),
};
}),
);
setLoadingComparatorSuggestions(false);
})
@@ -464,6 +561,7 @@ const AdhocFilterEditPopoverSimpleTabContent: FC<Props> = props => {
}, [
props.adhocFilter.subject,
props.adhocFilter.clause,
props.adhocFilter.operatorId,
props.datasource,
datePicker,
]);
@@ -44,6 +44,17 @@ export const OPERATORS_TO_SQL = {
'IS NULL': 'IS NULL',
'IS TRUE': 'IS TRUE',
'IS FALSE': 'IS FALSE',
// Element-level array operators (shown as filter labels; not executable SQL —
// the Custom SQL tab is hidden for these).
CONTAINS_ANY: 'CONTAINS ANY',
CONTAINS_ALL: 'CONTAINS ALL',
IS_EMPTY: 'IS EMPTY',
IS_NOT_EMPTY: 'IS NOT EMPTY',
LENGTH_EQUALS: 'LENGTH =',
LENGTH_GREATER_THAN: 'LENGTH >',
LENGTH_LESS_THAN: 'LENGTH <',
LENGTH_GREATER_THAN_OR_EQUALS: 'LENGTH >=',
LENGTH_LESS_THAN_OR_EQUALS: 'LENGTH <=',
'LATEST PARTITION': ({
datasource,
}: {
@@ -340,7 +340,9 @@ test('Should filter saved metrics by metric_name and verbose_name', async () =>
await userEvent.type(combobox, 'revenue');
let dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
let dropdown = document.querySelector(
'.ant-select-dropdown-list',
) as HTMLElement;
expect(within(dropdown).getByText('Gross Revenue')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Count')).not.toBeInTheDocument();
expect(within(dropdown).queryByText('Average Price')).not.toBeInTheDocument();
@@ -352,7 +354,7 @@ test('Should filter saved metrics by metric_name and verbose_name', async () =>
await userEvent.clear(combobox);
await userEvent.type(combobox, 'Unique');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Unique Users')).toBeInTheDocument();
expect(within(dropdown).queryByText('Total Count')).not.toBeInTheDocument();
expect(within(dropdown).queryByText('Gross Revenue')).not.toBeInTheDocument();
@@ -360,7 +362,7 @@ test('Should filter saved metrics by metric_name and verbose_name', async () =>
await userEvent.clear(combobox);
await userEvent.type(combobox, 'total');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Total Count')).toBeInTheDocument();
expect(within(dropdown).getByText('Total Quantity')).toBeInTheDocument();
expect(within(dropdown).queryByText('Gross Revenue')).not.toBeInTheDocument();
@@ -421,7 +423,9 @@ test('Should filter columns by column_name and verbose_name in Simple tab', asyn
await userEvent.type(columnCombobox, 'product');
let dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
let dropdown = document.querySelector(
'.ant-select-dropdown-list',
) as HTMLElement;
expect(within(dropdown).getByText('Product Title')).toBeInTheDocument();
expect(
within(dropdown).queryByText('User Identifier'),
@@ -435,7 +439,7 @@ test('Should filter columns by column_name and verbose_name in Simple tab', asyn
await userEvent.clear(columnCombobox);
await userEvent.type(columnCombobox, 'Modified');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Last Modified')).toBeInTheDocument();
expect(
within(dropdown).queryByText('User Identifier'),
@@ -445,7 +449,7 @@ test('Should filter columns by column_name and verbose_name in Simple tab', asyn
await userEvent.clear(columnCombobox);
await userEvent.type(columnCombobox, '_at');
dropdown = document.querySelector('.rc-virtual-list') as HTMLElement;
dropdown = document.querySelector('.ant-select-dropdown-list') as HTMLElement;
expect(within(dropdown).getByText('Creation Timestamp')).toBeInTheDocument();
expect(within(dropdown).getByText('Last Modified')).toBeInTheDocument();
expect(
+52 -1
View File
@@ -45,6 +45,17 @@ export enum Operators {
IsTrue = 'IS_TRUE',
IsFalse = 'IS_FALSE',
TemporalRange = 'TEMPORAL_RANGE',
// Element-level operators for multi-value (array) columns
ContainsAny = 'CONTAINS_ANY',
ContainsAll = 'CONTAINS_ALL',
IsEmpty = 'IS_EMPTY',
IsNotEmpty = 'IS_NOT_EMPTY',
// Length (element-count) comparison operators for array columns
LengthEquals = 'LENGTH_EQUALS',
LengthGreaterThan = 'LENGTH_GREATER_THAN',
LengthLessThan = 'LENGTH_LESS_THAN',
LengthGreaterThanOrEqual = 'LENGTH_GREATER_THAN_OR_EQUALS',
LengthLessThanOrEqual = 'LENGTH_LESS_THAN_OR_EQUALS',
}
export interface OperatorType {
@@ -89,6 +100,39 @@ export const OPERATOR_ENUM_TO_OPERATOR_TYPE: {
display: t('TEMPORAL_RANGE'),
operation: 'TEMPORAL_RANGE',
},
[Operators.ContainsAny]: {
display: t('Contains any'),
operation: 'CONTAINS_ANY',
},
[Operators.ContainsAll]: {
display: t('Contains all'),
operation: 'CONTAINS_ALL',
},
[Operators.IsEmpty]: { display: t('Is empty'), operation: 'IS_EMPTY' },
[Operators.IsNotEmpty]: {
display: t('Is not empty'),
operation: 'IS_NOT_EMPTY',
},
[Operators.LengthEquals]: {
display: t('Length equals (=)'),
operation: 'LENGTH_EQUALS',
},
[Operators.LengthGreaterThan]: {
display: t('Length greater than (>)'),
operation: 'LENGTH_GREATER_THAN',
},
[Operators.LengthLessThan]: {
display: t('Length less than (<)'),
operation: 'LENGTH_LESS_THAN',
},
[Operators.LengthGreaterThanOrEqual]: {
display: t('Length greater or equal (>=)'),
operation: 'LENGTH_GREATER_THAN_OR_EQUALS',
},
[Operators.LengthLessThanOrEqual]: {
display: t('Length less or equal (<=)'),
operation: 'LENGTH_LESS_THAN_OR_EQUALS',
},
};
export const OPERATORS_OPTIONS = Object.values(Operators) as Operators[];
@@ -105,7 +149,12 @@ export const HAVING_OPERATORS = [
Operators.GreaterThan,
Operators.GreaterThanOrEqual,
];
export const MULTI_OPERATORS = new Set([Operators.In, Operators.NotIn]);
export const MULTI_OPERATORS = new Set([
Operators.In,
Operators.NotIn,
Operators.ContainsAny,
Operators.ContainsAll,
]);
// CUSTOM_OPERATORS will show operator in simple mode,
// but will generate customized sqlExpression
export const CUSTOM_OPERATORS = new Set([
@@ -120,6 +169,8 @@ export const DISABLE_INPUT_OPERATORS = [
Operators.LatestPartition,
Operators.IsTrue,
Operators.IsFalse,
Operators.IsEmpty,
Operators.IsNotEmpty,
];
export const sqlaAutoGeneratedMetricNameRegex =
@@ -82,3 +82,14 @@ test('Should handle boolean true comparator as a string value', () => {
"subject operator 'TRUE'",
);
});
test('Should render array-literal comparators as-is (not quoted)', () => {
// Whole-array = filter: the pasted array literal is shown unquoted.
expect(getSimpleSQLExpression('ingredients', '=', "['1 large egg']")).toBe(
"ingredients = ['1 large egg']",
);
// IN with multiple array literals.
expect(
getSimpleSQLExpression('ingredients', Operators.In, ["['a']", "['b']"]),
).toBe(`ingredients ${Operators.In} (['a'], ['b'])`);
});
@@ -461,10 +461,15 @@ export const getSimpleSQLExpression = (
if (comparatorArray.length > 0 && showComparator) {
const formattedComparators = comparatorArray
.map(val => optionLabel(val))
.map(
val =>
`${quote}${isString ? String(val).replace(/'/g, "''") : val}${quote}`,
);
.map(val => {
// Array-literal values (e.g. ['a', 'b']) are shown as-is rather than
// quoted/escaped as a string, so array-column filters read naturally.
const asString = String(val);
if (asString.startsWith('[') && asString.endsWith(']')) {
return asString;
}
return `${quote}${isString ? asString.replace(/'/g, "''") : val}${quote}`;
});
expression += ` ${prefix}${formattedComparators.join(', ')}${suffix}`;
}
}
@@ -27,8 +27,15 @@ import {
Input,
Button,
Modal,
Select,
} from '@superset-ui/core/components';
import { useToasts } from 'src/components/MessageToasts/withToasts';
import copyTextToClipboard from 'src/utils/copy';
import {
API_KEY_SCOPE_OPTIONS,
getApiKeyScopesHelpText,
serializeApiKeyScopes,
} from './apiKeyScopes';
interface ApiKeyCreateModalProps {
show: boolean;
@@ -38,6 +45,7 @@ interface ApiKeyCreateModalProps {
interface FormValues {
name: string;
scopes?: string[];
}
export function ApiKeyCreateModal({
@@ -62,9 +70,13 @@ export function ApiKeyCreateModal({
const handleFormSubmit = async (values: FormValues) => {
try {
const scopes = serializeApiKeyScopes(values.scopes);
const response = await SupersetClient.post({
endpoint: '/api/v1/security/api_keys/',
jsonPayload: values,
jsonPayload: {
name: values.name,
...(scopes && { scopes }),
},
});
const key = response.json?.result?.key;
if (!key) {
@@ -83,7 +95,7 @@ export function ApiKeyCreateModal({
return;
}
try {
await navigator.clipboard.writeText(createdKey);
await copyTextToClipboard(() => Promise.resolve(createdKey));
setCopied(true);
if (copyTimerRef.current) {
clearTimeout(copyTimerRef.current);
@@ -170,6 +182,24 @@ export function ApiKeyCreateModal({
placeholder={t('e.g., CI/CD Pipeline, Analytics Script')}
/>
</FormItem>
<FormItem
name="scopes"
label={t('MCP scopes')}
help={getApiKeyScopesHelpText()}
>
<Select
name="scopes"
mode="multiple"
allowClear
showSearch
options={API_KEY_SCOPE_OPTIONS}
placeholder={t('Select MCP resource scopes (optional)')}
data-test="api-key-scopes-select"
getPopupContainer={(trigger: HTMLElement) =>
trigger.closest<HTMLElement>('.ant-modal-container') ?? trigger
}
/>
</FormItem>
</FormModal>
);
}
@@ -162,6 +162,19 @@ export function ApiKeyList() {
key: 'status',
render: (_: unknown, record: ApiKey) => getStatusBadge(record),
},
{
title: t('MCP scopes'),
dataIndex: 'scopes',
key: 'scopes',
render: (scopes: string | null) =>
scopes ? (
<Tooltip title={scopes}>
<Tag>{t('%s MCP scopes', scopes.split(',').length)}</Tag>
</Tooltip>
) : (
<Tag>{t('RBAC only')}</Tag>
),
},
{
title: t('Actions'),
key: 'actions',
@@ -0,0 +1,50 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import {
API_KEY_SCOPE_OPTIONS,
getApiKeyScopesHelpText,
serializeApiKeyScopes,
} from './apiKeyScopes';
test('offers read and write scopes for every supported resource', () => {
expect(API_KEY_SCOPE_OPTIONS).toHaveLength(32);
expect(API_KEY_SCOPE_OPTIONS).toContainEqual({
label: 'superset:dashboard:read',
value: 'superset:dashboard:read',
});
expect(API_KEY_SCOPE_OPTIONS).toContainEqual({
label: 'superset:sqllab:write',
value: 'superset:sqllab:write',
});
});
test('serializes selected scopes for the FAB API', () => {
expect(
serializeApiKeyScopes(['superset:dashboard:read', 'superset:chart:write']),
).toBe('superset:dashboard:read,superset:chart:write');
expect(serializeApiKeyScopes([])).toBeUndefined();
expect(serializeApiKeyScopes()).toBeUndefined();
});
test('explains that scopes apply to MCP rather than REST APIs', () => {
expect(getApiKeyScopesHelpText()).toContain('MCP resources');
expect(getApiKeyScopesHelpText()).toContain(
'do not restrict REST API requests',
);
});
@@ -0,0 +1,55 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import { t } from '@apache-superset/core/translation';
const API_KEY_SCOPE_RESOURCES = [
'annotation',
'chart',
'dashboard',
'database',
'dataset',
'explore',
'query',
'report',
'role',
'rls',
'savedquery',
'sqllab',
'tag',
'task',
'theme',
'user',
] as const;
const API_KEY_SCOPE_ACTIONS = ['read', 'write'] as const;
export const API_KEY_SCOPE_OPTIONS = API_KEY_SCOPE_RESOURCES.flatMap(resource =>
API_KEY_SCOPE_ACTIONS.map(action => {
const value = `superset:${resource}:${action}`;
return { label: value, value };
}),
);
export const serializeApiKeyScopes = (scopes?: string[]) =>
scopes?.length ? scopes.join(',') : undefined;
export const getApiKeyScopesHelpText = () =>
t(
'Limit which MCP resources and actions this key can access. These scopes do not restrict REST API requests and never grant permissions the user does not already have. Leave empty for legacy RBAC-only behavior.',
);
@@ -88,9 +88,9 @@ test('PermissionsField shows a permission matched by its raw name even though th
),
);
expect(
await within(document.querySelector('.rc-virtual-list')!).findByText(
'stg silver',
),
await within(
document.querySelector('.ant-select-dropdown-list')!,
).findByText('stg silver'),
).toBeInTheDocument();
});
@@ -31,7 +31,12 @@ import {
import { Group, Role, UserObject } from 'src/pages/UsersList/types';
import { Actions } from 'src/constants';
import { BaseUserListModalProps, FormValues } from './types';
import { createUser, updateUser, atLeastOneRoleOrGroup } from './utils';
import {
createUser,
updateUser,
atLeastOneRoleOrGroup,
handleUserError,
} from './utils';
export interface UserModalProps extends BaseUserListModalProps {
roles: Role[];
@@ -51,36 +56,6 @@ function UserListModal({
}: UserModalProps) {
const { addDangerToast, addSuccessToast } = useToasts();
const handleFormSubmit = async (values: FormValues) => {
const handleError = async (
err: any,
action: Actions.CREATE | Actions.UPDATE,
) => {
let errorMessage =
action === Actions.CREATE
? t('There was an error creating the user. Please, try again.')
: t('There was an error updating the user. Please, try again.');
if (err.status === 422) {
const errorData = await err.json();
const detail = errorData?.message || '';
if (detail.includes('duplicate key value')) {
if (detail.includes('ab_user_username_key')) {
errorMessage = t(
'This username is already taken. Please choose another one.',
);
} else if (detail.includes('ab_user_email_key')) {
errorMessage = t(
'This email is already associated with an account. Please choose another one.',
);
}
}
}
addDangerToast(errorMessage);
throw err;
};
if (isEditMode) {
if (!user) {
throw new Error('User is required in edit mode');
@@ -89,14 +64,14 @@ function UserListModal({
await updateUser(user.id, values);
addSuccessToast(t('The user has been updated successfully.'));
} catch (err) {
await handleError(err, Actions.UPDATE);
await handleUserError(err as Response, Actions.UPDATE, addDangerToast);
}
} else {
try {
await createUser(values);
addSuccessToast(t('The user has been created successfully.'));
} catch (err) {
await handleError(err, Actions.CREATE);
await handleUserError(err as Response, Actions.CREATE, addDangerToast);
}
}
};
@@ -0,0 +1,99 @@
/**
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/
import { Actions } from 'src/constants';
import { handleUserError } from './utils';
test('shows the password validation message from a 400 response', async () => {
const error = new Response(
JSON.stringify({
message: {
password: ['Password must be at least 8 characters long.'],
},
}),
{ status: 400 },
);
const addDangerToast = jest.fn();
await expect(
handleUserError(error, Actions.CREATE, addDangerToast),
).rejects.toBe(error);
expect(addDangerToast).toHaveBeenCalledWith(
'Password must be at least 8 characters long.',
);
});
test('shows a plain string message from a 400 response', async () => {
const error = new Response(
JSON.stringify({ message: 'User must have at least one role or group!' }),
{ status: 400 },
);
const addDangerToast = jest.fn();
await expect(
handleUserError(error, Actions.UPDATE, addDangerToast),
).rejects.toBe(error);
expect(addDangerToast).toHaveBeenCalledWith(
'User must have at least one role or group!',
);
});
test('keeps the duplicate username message for a 422 response', async () => {
const error = new Response(
JSON.stringify({
message:
'duplicate key value violates unique constraint "ab_user_username_key"',
}),
{ status: 422 },
);
const addDangerToast = jest.fn();
await expect(
handleUserError(error, Actions.CREATE, addDangerToast),
).rejects.toBe(error);
expect(addDangerToast).toHaveBeenCalledWith(
'This username is already taken. Please choose another one.',
);
});
test('shows the generic message when a 422 response has no message', async () => {
const error = new Response(JSON.stringify({ foo: 'bar' }), { status: 422 });
const addDangerToast = jest.fn();
await expect(
handleUserError(error, Actions.CREATE, addDangerToast),
).rejects.toBe(error);
expect(addDangerToast).toHaveBeenCalledWith(
'There was an error creating the user. Please, try again.',
);
});
test('shows the generic message when a 400 response is not JSON', async () => {
const error = new Response('<html>Bad request</html>', {
status: 400,
headers: { 'Content-Type': 'text/html' },
});
const addDangerToast = jest.fn();
await expect(
handleUserError(error, Actions.CREATE, addDangerToast),
).rejects.toBe(error);
expect(addDangerToast).toHaveBeenCalledWith(
'There was an error creating the user. Please, try again.',
);
});
+40 -1
View File
@@ -17,10 +17,49 @@
* under the License.
*/
import { t } from '@apache-superset/core/translation';
import { SupersetClient } from '@superset-ui/core';
import { getClientErrorObject, SupersetClient } from '@superset-ui/core';
import { SelectOption } from 'src/components/ListView';
import { Actions } from 'src/constants';
import { FormValues } from './types';
type AddDangerToast = (message: string) => void;
export const handleUserError = async (
err: Response,
action: Actions.CREATE | Actions.UPDATE,
addDangerToast: AddDangerToast,
): Promise<never> => {
let errorMessage =
action === Actions.CREATE
? t('There was an error creating the user. Please, try again.')
: t('There was an error updating the user. Please, try again.');
if (err.status === 400 || err.status === 422) {
const errorData = await getClientErrorObject(err);
const message: unknown = errorData.message;
if (err.status === 400 && message && errorData.error) {
errorMessage = errorData.error;
} else if (
err.status === 422 &&
errorData.error?.includes('duplicate key value')
) {
if (errorData.error.includes('ab_user_username_key')) {
errorMessage = t(
'This username is already taken. Please choose another one.',
);
} else if (errorData.error.includes('ab_user_email_key')) {
errorMessage = t(
'This email is already associated with an account. Please choose another one.',
);
}
}
}
addDangerToast(errorMessage);
throw err;
};
export const createUser = async (values: FormValues) => {
const { confirmPassword: _confirmPassword, ...payload } = values;
if (payload.active == null) {
@@ -1157,6 +1157,34 @@ test('dataset links use internal routing when PREVENT_UNSAFE_DEFAULT_URLS_ON_DAT
});
});
test('legacy dashboard default URLs use the registered client route', async () => {
const dataset = {
...mockDatasets[0],
explore_url: '/superset/dashboard/123/?standalone=1#section',
};
mockDatasetListEndpoints({ result: [dataset], count: 1 });
renderDatasetList(
mockAdminUser,
{},
{
common: {
conf: {
PREVENT_UNSAFE_DEFAULT_URLS_ON_DATASET: true,
},
},
},
);
const datasetLink = await screen.findByRole('link', {
name: dataset.table_name,
});
expect(datasetLink).toHaveAttribute(
'href',
'/dashboard/123/?standalone=1#section',
);
});
// Note: These delete error tests verify that the modal doesn't open when fetching
// related_objects fails. The component's openDatasetDeleteModal error handler
// (index.tsx:262-268) returns a string but doesn't call addDangerToast(), so no
@@ -54,10 +54,18 @@ import {
const APP_ROOT = '/superset';
const renderUnderSubdirectory = () => {
const renderUnderSubdirectory = (preventUnsafeDefaultUrls = false) => {
const defaultState = createDefaultStoreState(mockAdminUser);
const store = createMockStore({
...createDefaultStoreState(mockAdminUser),
...defaultState,
user: mockAdminUser,
common: {
...defaultState.common,
conf: {
...defaultState.common?.conf,
PREVENT_UNSAFE_DEFAULT_URLS_ON_DATASET: preventUnsafeDefaultUrls,
},
},
});
return render(
<Provider store={store}>
@@ -115,6 +123,31 @@ test('explore link is single-prefixed under a subdirectory deployment', async ()
expect(exploreLink.getAttribute('href')).not.toContain('/superset/superset');
});
test('legacy dashboard default URL uses the router basename once', async () => {
// A subdirectory user pastes the full browser path, so the saved value
// carries both the application root and the legacy `/superset` prefix.
// stripAppRoot removes the root and the legacy normalization removes the
// prefix, leaving the basename to re-add the root exactly once.
const dataset = {
...mockDatasets[0],
explore_url: `${APP_ROOT}/superset/dashboard/123/?standalone=1#section`,
};
mockDatasetListEndpoints({ result: [dataset], count: 1 });
renderUnderSubdirectory(true);
const dashboardLink = await screen.findByRole('link', {
name: dataset.table_name,
});
expect(dashboardLink).toHaveAttribute(
'href',
`${APP_ROOT}/dashboard/123/?standalone=1#section`,
);
expect(dashboardLink.getAttribute('href')).not.toContain(
'/superset/superset',
);
});
test('external default_endpoint passes through unprefixed', async () => {
const dataset = {
...mockDatasets[0],
@@ -87,7 +87,6 @@ import withToasts from 'src/components/MessageToasts/withToasts';
import { Icons } from '@superset-ui/core/components/Icons';
import WarningIconWithTooltip from '@superset-ui/core/components/WarningIconWithTooltip';
import { isUserEditorOrAdmin } from 'src/dashboard/util/permissionUtils';
import {
PAGE_SIZE,
SORT_BY,
@@ -114,6 +113,10 @@ import type {
} from 'src/types/bootstrapTypes';
import type User from 'src/types/User';
// Keep saved Default URLs compatible with the prefix-free SPA route.
const normalizeLegacyDashboardUrl = (url: string) =>
url.replace(/^\/superset(?=\/dashboard(?:\/|$))/, '');
const SEMANTIC_LAYERS_FLAG = 'SEMANTIC_LAYERS' as FeatureFlag;
type DatasetExtra = {
certification?: {
@@ -722,7 +725,9 @@ const DatasetList: FunctionComponent<DatasetListProps> = ({
// Router basename, which re-prefixes the root — so strip it here to
// avoid a doubled `/superset/superset/...`. External
// `default_endpoint` URLs pass through unchanged.
const exploreTo = stripAppRoot(exploreURL);
const exploreTo = normalizeLegacyDashboardUrl(
stripAppRoot(exploreURL),
);
let titleLink: JSX.Element;
if (PREVENT_UNSAFE_DEFAULT_URLS_ON_DATASET) {
titleLink = (
+148 -148
View File
@@ -24,15 +24,15 @@
"@types/lodash-es": "^4.17.12",
"@types/node": "^26.2.0",
"@types/ws": "^8.18.1",
"@typescript-eslint/eslint-plugin": "^8.65.0",
"@typescript-eslint/parser": "^8.66.0",
"@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.67.0",
"eslint": "^10.8.1",
"eslint-config-prettier": "^10.1.8",
"globals": "^17.9.0",
"oxfmt": "^0.62.0",
"globals": "^17.10.0",
"oxfmt": "^0.63.0",
"tscw-config": "^1.1.2",
"typescript": "^6.0.3",
"typescript-eslint": "^8.66.0",
"typescript-eslint": "^8.67.0",
"vitest": "^4.1.10"
},
"engines": {
@@ -310,9 +310,9 @@
}
},
"node_modules/@oxfmt/binding-android-arm-eabi": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-android-arm-eabi/-/binding-android-arm-eabi-0.62.0.tgz",
"integrity": "sha512-pdsv0C4gPjJ8H1+sd8u0BDx+yLACTL+rgeMIOL1ln4ihSnhw8CWXtYWgvcSkyTfgGBIzFKab+d8rx9Xl4en/Kw==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-android-arm-eabi/-/binding-android-arm-eabi-0.63.0.tgz",
"integrity": "sha512-YmRth4ZPGgEXcgmkhvANbC9uD67dxmSobW7DQuyt5tOBOKvPnIpk5SVHBj88E+7wMNRI2FhqaDbOhQFBix+b8A==",
"cpu": [
"arm"
],
@@ -327,9 +327,9 @@
}
},
"node_modules/@oxfmt/binding-android-arm64": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-android-arm64/-/binding-android-arm64-0.62.0.tgz",
"integrity": "sha512-WC3YQ7uS/KtDrjmqwBviwFKe9qeoi+eXx8aX1z/ffG23Md75myjrJaQqTuJvdOLPoa4EYTjDWH0dHXfwulCVog==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-android-arm64/-/binding-android-arm64-0.63.0.tgz",
"integrity": "sha512-icbahX8X2X3sRamOMecvdYeZXWjPDazRDIfvWfy7Ca1nc/ZDT2Y9k5Nt7s46EqFd7NQPdgk+CM3/SgIT5LPCaQ==",
"cpu": [
"arm64"
],
@@ -344,9 +344,9 @@
}
},
"node_modules/@oxfmt/binding-darwin-arm64": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-darwin-arm64/-/binding-darwin-arm64-0.62.0.tgz",
"integrity": "sha512-GM8Yf3LjjaR1I8PD0SfeoIlwhsh9GvSF+cQ8sf624Yxnjsyumn95aFzYfKJVefblfDIiOAnZ7QVm2sa21Er/0Q==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-darwin-arm64/-/binding-darwin-arm64-0.63.0.tgz",
"integrity": "sha512-WV+Ze5v5gI2qoj8jpAovt8KBTW8pjEz/AiMXXjeTQS+Bmf/MmZXTS40S8xNPDszX+W8WDv2Bbk6qKrMTtUGu1A==",
"cpu": [
"arm64"
],
@@ -361,9 +361,9 @@
}
},
"node_modules/@oxfmt/binding-darwin-x64": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-darwin-x64/-/binding-darwin-x64-0.62.0.tgz",
"integrity": "sha512-d5THp7F8bCxLqNogEXDORRsQD6dosf3EyFtnXfBer6v+8tGdcWIjoDX9WaXrrF/26zOmL8qHpPTKCEvpBDmZkQ==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-darwin-x64/-/binding-darwin-x64-0.63.0.tgz",
"integrity": "sha512-CJGSBdDxXOWIpoFXHpverimCvz084KA7L483rqJ44c3jDtzv6d4qOSoR/V9ywSHfV+Ks1lwIj2P49BFhunLNAA==",
"cpu": [
"x64"
],
@@ -378,9 +378,9 @@
}
},
"node_modules/@oxfmt/binding-freebsd-x64": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-freebsd-x64/-/binding-freebsd-x64-0.62.0.tgz",
"integrity": "sha512-1DnrtXGZooOZ0fHgAXZUaDQzBVh1CM2MNW4oBXyQ2aWKvCHjyljvT9fgBkOM0fEOb96X5eqtcfJ0YUVt9jj66g==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-freebsd-x64/-/binding-freebsd-x64-0.63.0.tgz",
"integrity": "sha512-BDfKY+KhL2078cgswBBFQPAYuxCy93bS/iC5frdSeSbTLcGrR6VC2hsuPTanoJmg84+wSyWl0wWC1eR+uTnkRg==",
"cpu": [
"x64"
],
@@ -395,9 +395,9 @@
}
},
"node_modules/@oxfmt/binding-linux-arm-gnueabihf": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-0.62.0.tgz",
"integrity": "sha512-4pQDHOYRH+Huqe0StIaWyvk2CVl/aTaqSrbZpA3/pLS2xH24ME7lBgYprhQF2fRkHBzhGGGKliwxFsDdHwx59g==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-0.63.0.tgz",
"integrity": "sha512-Ov1cQEXT4mj7cojAokWSS1eoxkoyvbDfAbxNsGIKY2o36kvdAaFzPxRN6NxFRk9fD72B8oCoTTX/NuYTUWlpsg==",
"cpu": [
"arm"
],
@@ -412,9 +412,9 @@
}
},
"node_modules/@oxfmt/binding-linux-arm-musleabihf": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm-musleabihf/-/binding-linux-arm-musleabihf-0.62.0.tgz",
"integrity": "sha512-X0jAaZJFMCVKhB6YyWVTQ/wN2DLsBcZKSMqTS76bF6riT+XZdtg2FPEdjDvdVbunO9cG+tWiVaEs4Zs38lxYog==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm-musleabihf/-/binding-linux-arm-musleabihf-0.63.0.tgz",
"integrity": "sha512-0LE7ro3+6L79jcMANycAZfRaC7zxr9YZ2+vEL5uMD9QlEep+rS/r1kSJsnuLl991NXJZD60euh0PC1GHrR20vw==",
"cpu": [
"arm"
],
@@ -429,9 +429,9 @@
}
},
"node_modules/@oxfmt/binding-linux-arm64-gnu": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-0.62.0.tgz",
"integrity": "sha512-682Z8T5s8T5ATArYtsejKvbIfd8LEAXyyDkKkoZVq8HND7Vx8TYLlrDjDSeYfodMeVwHOgkj13lJYR8cj6vUSg==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-0.63.0.tgz",
"integrity": "sha512-izPk+2Z4gjuZK32Fqh5qXoMpT/2NXzLh++ob57HiEiVSQZ1iYXu8EKMzb+K5AvWyIEXhdDIt7ADjGGtFhkT9Bw==",
"cpu": [
"arm64"
],
@@ -449,9 +449,9 @@
}
},
"node_modules/@oxfmt/binding-linux-arm64-musl": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm64-musl/-/binding-linux-arm64-musl-0.62.0.tgz",
"integrity": "sha512-lk25fAl7KWaLWVJcW0CHEXB7QlQZtx5eDkjpaGMK0hzXTjUe0Wmlu8IKuFHoviSOcEJedRTs4VE/506VqGxGew==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-arm64-musl/-/binding-linux-arm64-musl-0.63.0.tgz",
"integrity": "sha512-alPmbOuWXFXiSo+lOtv6X71C7SYMEDW2WVvywOvf9BwKgEhSNGhMTLeFVSjKUMCamcjbbgVdsWF8GN1uy8xshg==",
"cpu": [
"arm64"
],
@@ -469,9 +469,9 @@
}
},
"node_modules/@oxfmt/binding-linux-ppc64-gnu": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-0.62.0.tgz",
"integrity": "sha512-SFyNqHQLwySceWNLhiSldx7wPXRAzP0L0WcW9GegP3uWrpZGJiZlQO85NbHAFPEfxR9PhZ9qSnZryEh7+v+4Gw==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-0.63.0.tgz",
"integrity": "sha512-BdzCPvolJc4AWZ+YMzgUDJcDzbQWrFjYuqBHoNHNqP1aCaluQRJNs4k3vNU5IG7vTpjf9zeD73D7MFM1TecZpg==",
"cpu": [
"ppc64"
],
@@ -489,9 +489,9 @@
}
},
"node_modules/@oxfmt/binding-linux-riscv64-gnu": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-riscv64-gnu/-/binding-linux-riscv64-gnu-0.62.0.tgz",
"integrity": "sha512-KYj55C1ywJfHo6+aKDuEmUtVEdJALsC5GwayDGsI6FGz2GxFqNr/mA8nxVsNbJzm7sE5MRqTQ9ziImSzhYXysA==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-riscv64-gnu/-/binding-linux-riscv64-gnu-0.63.0.tgz",
"integrity": "sha512-7sIgfLzqtNKSkMGsGVyRpHwpjNezRg2XONvUOheFZs95TSZpM0JAuPpA8KrQFsWc4wPU95roX2O69JgH8igOgw==",
"cpu": [
"riscv64"
],
@@ -509,9 +509,9 @@
}
},
"node_modules/@oxfmt/binding-linux-riscv64-musl": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-riscv64-musl/-/binding-linux-riscv64-musl-0.62.0.tgz",
"integrity": "sha512-BhZDNo5GOU5nC378RhD0/XpvaEBHsH3HLgJp8YZX3A0InC7oivzA63HsRmiXFLtLSHAstEVrDf6fbC7Rs8Jh/A==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-riscv64-musl/-/binding-linux-riscv64-musl-0.63.0.tgz",
"integrity": "sha512-9Tcg0y0WcVa6Mm9AgcgFMseDS+VkFJZpKZ8We9SpDY4gg5jewSwln+0sO04QLcTS1BtfDl9MwR+NfID8L7PUTg==",
"cpu": [
"riscv64"
],
@@ -529,9 +529,9 @@
}
},
"node_modules/@oxfmt/binding-linux-s390x-gnu": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-0.62.0.tgz",
"integrity": "sha512-UyAFmyHkgSgUJ/wOM4p3U8AC2yAFvRH5PNBs7TnK0fObTT/XSWcdr/lAzPSWaekHaZFaMeFZyk9n93Joq3J93A==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-0.63.0.tgz",
"integrity": "sha512-qWKC1pEOpx1qYhXaugPhHUeXwSfqEOk2wJH2LqVXGPV5iQYfdAZdt+d2XDiX4DTSWA2QDMUcFB+wEORh3Xn/sA==",
"cpu": [
"s390x"
],
@@ -549,9 +549,9 @@
}
},
"node_modules/@oxfmt/binding-linux-x64-gnu": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-x64-gnu/-/binding-linux-x64-gnu-0.62.0.tgz",
"integrity": "sha512-1iYMP0leytWazFubD/WnINJuIrzRPuoL1aWEJdlGezEzDbTxcd29R4r8IUzP2oWeKst5V02uMJgR2NILlPlG6w==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-x64-gnu/-/binding-linux-x64-gnu-0.63.0.tgz",
"integrity": "sha512-S9wXYOiGSqYGS4Fx/TFsY+xDd/7dE5s+rUgbA4TsHiVF9e8J3ZcKmP7dsP/7iqLI9Wz7Ic7TzEr3mdthRCTdrA==",
"cpu": [
"x64"
],
@@ -569,9 +569,9 @@
}
},
"node_modules/@oxfmt/binding-linux-x64-musl": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-x64-musl/-/binding-linux-x64-musl-0.62.0.tgz",
"integrity": "sha512-4rA/URtJSTVNVAQz6Q8wf7SaRvOXVy+TizriT9hs/Y1XhLR/R+92uWKRQG8yFWRAIEBbFHJ6WevQcl/G9SXEfw==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-linux-x64-musl/-/binding-linux-x64-musl-0.63.0.tgz",
"integrity": "sha512-5eGyTJuMZNwBSHCivXt8Yuta6GeTYksOPXRk2MIhajiyFGQx7bjaHIwY+ZusAoFHhT157A9x6sktLjYo9D5oMQ==",
"cpu": [
"x64"
],
@@ -589,9 +589,9 @@
}
},
"node_modules/@oxfmt/binding-openharmony-arm64": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-openharmony-arm64/-/binding-openharmony-arm64-0.62.0.tgz",
"integrity": "sha512-mSZuFHU2ar1KLUjXpI2QBQcJ1VsOB3mOCgQXuXCpKs19dgh4u+OaovNfrWDfiJb+ihJ2+f7YFcaO9bS2dlTCXA==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-openharmony-arm64/-/binding-openharmony-arm64-0.63.0.tgz",
"integrity": "sha512-Rz7hx+Dv3DoW/S6pwVAyjfFXp7/trdQ1zg+vNmsdsdDNlUccugp4XNqambSuEAeP0DaG9k72AtNyfDXCEg0AGw==",
"cpu": [
"arm64"
],
@@ -606,9 +606,9 @@
}
},
"node_modules/@oxfmt/binding-win32-arm64-msvc": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-0.62.0.tgz",
"integrity": "sha512-OfwuhkcjDlqC4EgDojtiV9mzpLqeB9KqTOWPOjLEYBVdDCVSxqW3qzp/xcIxsbtI0UgGCnKvAqYKyY25kf5JZw==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-0.63.0.tgz",
"integrity": "sha512-T/IuizKN9mr4Xw6YYnptkXRNdLkyIlUZ7c8zfTOBpoytZyJ1BAsMUvsMDEx0X4YvSMpaivm+DR8112rQfzC25g==",
"cpu": [
"arm64"
],
@@ -623,9 +623,9 @@
}
},
"node_modules/@oxfmt/binding-win32-ia32-msvc": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-ia32-msvc/-/binding-win32-ia32-msvc-0.62.0.tgz",
"integrity": "sha512-P9uDDNFRzghO3X8QAzhkjKhK7JvtABsVn8UYtFX7uor12IAnwNt8nNIctvfWj1JkQU/kE+fmLRPiw7XlrIHsZw==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-ia32-msvc/-/binding-win32-ia32-msvc-0.63.0.tgz",
"integrity": "sha512-XjrO5FJ5Wl9vsAxtCP1G/eaeT6y1K2s9CICUHGE42cEjou32/J6S+B1KnrOAboj6E7uhJnwPbRSvznWcxNdA0g==",
"cpu": [
"ia32"
],
@@ -640,9 +640,9 @@
}
},
"node_modules/@oxfmt/binding-win32-x64-msvc": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-x64-msvc/-/binding-win32-x64-msvc-0.62.0.tgz",
"integrity": "sha512-dlI5SY7XYQCiCBafntWagCR6HcAJB/NpsLtdlPx8x08+Osz8Ok1HHz1GZuusegCe/VoJ6pAnF5a4pd5OZAq7qQ==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/@oxfmt/binding-win32-x64-msvc/-/binding-win32-x64-msvc-0.63.0.tgz",
"integrity": "sha512-sgsHCQy432OTQH4Ikk3tZptp3GqwnhwUDuY0loBH41zyHWfMZY9v8Dy78wsnSofHejvFozZGgJgBB1A0LQRwMQ==",
"cpu": [
"x64"
],
@@ -1070,17 +1070,17 @@
}
},
"node_modules/@typescript-eslint/eslint-plugin": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.66.0.tgz",
"integrity": "sha512-p088eaGrzYz1s+7cov0aMOCkNGTJlVxF4jgubf28c8L0Cv9Rloj8YBHnv4hXLq6IIEE1AsjNWavO+k+8kP2Y0A==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/eslint-plugin/-/eslint-plugin-8.67.0.tgz",
"integrity": "sha512-Un7Heoyj65NREbKAyIrFxeM143NZpExWmy1Nep4DLeQOeLlTeumPjoNKnBrU5D5moWXbPJgRa5Uwcdu0faVNGQ==",
"dev": true,
"license": "MIT",
"dependencies": {
"@eslint-community/regexpp": "^4.12.2",
"@typescript-eslint/scope-manager": "8.66.0",
"@typescript-eslint/type-utils": "8.66.0",
"@typescript-eslint/utils": "8.66.0",
"@typescript-eslint/visitor-keys": "8.66.0",
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/type-utils": "8.67.0",
"@typescript-eslint/utils": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"ignore": "^7.0.5",
"natural-compare": "^1.4.0",
"ts-api-utils": "^2.5.0"
@@ -1093,22 +1093,22 @@
"url": "https://opencollective.com/typescript-eslint"
},
"peerDependencies": {
"@typescript-eslint/parser": "^8.66.0",
"@typescript-eslint/parser": "^8.67.0",
"eslint": "^8.57.0 || ^9.0.0 || ^10.0.0",
"typescript": ">=4.8.4 <6.1.0"
}
},
"node_modules/@typescript-eslint/parser": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.66.0.tgz",
"integrity": "sha512-X6ypGChaWYk6PBtUg2BwuTZEFFcHJAtGTVJ9/lCTOufhZ4i9fNolQNnktq+kkMCwMj7V8Svsq7+TxSDslmhE0g==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/parser/-/parser-8.67.0.tgz",
"integrity": "sha512-fUBfTuuEulWqX6V8+O3PtScV01tzYYRUDTAirHFKoRAt7nOzoGiPt0M/bB47wWNy0coOOcgEwAMUtBpykMxl6w==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/scope-manager": "8.66.0",
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/typescript-estree": "8.66.0",
"@typescript-eslint/visitor-keys": "8.66.0",
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3"
},
"engines": {
@@ -1124,14 +1124,14 @@
}
},
"node_modules/@typescript-eslint/project-service": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.66.0.tgz",
"integrity": "sha512-7MthGPTt4BP69lSryqpqq8HQqxuzynssckL/jyDyk3+TNMQ3y2jFWkptCrktWvBrP+EH787Nl5N5Qpw7WZg+5g==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/project-service/-/project-service-8.67.0.tgz",
"integrity": "sha512-cvE8c7ulYeXN9fYuszhCeCsbzyVEXuhrRCybnBre7TUmqb5nRmBfQAwCj0O3WJFDeyAZt4VYv51vMCC9LHSdYw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/tsconfig-utils": "^8.66.0",
"@typescript-eslint/types": "^8.66.0",
"@typescript-eslint/tsconfig-utils": "^8.67.0",
"@typescript-eslint/types": "^8.67.0",
"debug": "^4.4.3"
},
"engines": {
@@ -1146,14 +1146,14 @@
}
},
"node_modules/@typescript-eslint/scope-manager": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.66.0.tgz",
"integrity": "sha512-8TGcH25j9zqJ/IULB/ppyhRvxA8QYfFEZ7nfbg6/BN9spDgb8fPWQXlE5l8TWBL50EtUx007uZ1o9VOwrq2/9g==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/scope-manager/-/scope-manager-8.67.0.tgz",
"integrity": "sha512-EgvsleTwS4E+WzzSvem8fAUubLwatMNF1B5hHSLQxcvs7q2dtRhGyujHwLJSYlG41niJ7GP24Aha2+0mb1b2kg==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/visitor-keys": "8.66.0"
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
@@ -1164,9 +1164,9 @@
}
},
"node_modules/@typescript-eslint/tsconfig-utils": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.66.0.tgz",
"integrity": "sha512-9D5gLYZG4rOjcoag8MQ/fWI8WqA9wcPDyOGyWtWFhvM1lHRbliqUSPIY5J3zqCU1tvSwzXxnnjhQhz5Ne7mJ4g==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/tsconfig-utils/-/tsconfig-utils-8.67.0.tgz",
"integrity": "sha512-vV+LUSv5njUWsknE71fqKTlXUva+R76SaeORd6Zojcunk/6DvKFXONU3BrAs2H49mbygUXt6gbYunzwqNwlhdg==",
"dev": true,
"license": "MIT",
"engines": {
@@ -1181,15 +1181,15 @@
}
},
"node_modules/@typescript-eslint/type-utils": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.66.0.tgz",
"integrity": "sha512-LG2dWfjZQQp0ADtAu/EWJVayefGL2UEZ3CDeI44D9v3rXB/WYUqE/jpO28KrEKul5AySrmI+Zh1v6v+xW2U9+g==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/type-utils/-/type-utils-8.67.0.tgz",
"integrity": "sha512-aVWDXbRmdXO9siTfX4ditQI1T9+zVcNazT48EJCD0v40/9RIFoUgZ05CmGEq9H2gixRpjUn/iplwvlcvutJW/Q==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/typescript-estree": "8.66.0",
"@typescript-eslint/utils": "8.66.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0",
"@typescript-eslint/utils": "8.67.0",
"debug": "^4.4.3",
"ts-api-utils": "^2.5.0"
},
@@ -1206,9 +1206,9 @@
}
},
"node_modules/@typescript-eslint/types": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.66.0.tgz",
"integrity": "sha512-H6gcYaSDOyvL3AD/jHUtUFo2jqGgn/F6nuyuZSu0QTesxL+cP4dQoIMrODRofuJC09g64+WgZ6tE19Y1N2YIFQ==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/types/-/types-8.67.0.tgz",
"integrity": "sha512-sBtgslww8nsMYUjhdPBiSyUqSzT8uR6g93A2QXnQC8+cGdjz0CyaOdqHDRJb1AtORbZCNUJBBeFA/tNR2uQmww==",
"dev": true,
"license": "MIT",
"engines": {
@@ -1220,16 +1220,16 @@
}
},
"node_modules/@typescript-eslint/typescript-estree": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.66.0.tgz",
"integrity": "sha512-8/x4INiiQb10jGgXYD7116/zQ+OL84ZIFn0za68wwFHCanT/VLbBEroWht8RV8fn0/ZCAoazHLQgwUC0UQcDfg==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/typescript-estree/-/typescript-estree-8.67.0.tgz",
"integrity": "sha512-EKQBCE9yNlRJYm7jdTW5AhDacDUmSwQb0FAJAmK2EKYrNXIsa2vxcSZx6PvJ/dEdI6lS+Y9W+EXckLj0iPFGcw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/project-service": "8.66.0",
"@typescript-eslint/tsconfig-utils": "8.66.0",
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/visitor-keys": "8.66.0",
"@typescript-eslint/project-service": "8.67.0",
"@typescript-eslint/tsconfig-utils": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/visitor-keys": "8.67.0",
"debug": "^4.4.3",
"minimatch": "^10.2.2",
"semver": "^7.7.3",
@@ -1248,16 +1248,16 @@
}
},
"node_modules/@typescript-eslint/utils": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.66.0.tgz",
"integrity": "sha512-jasearZPolBw5NJNYGMwxzHMF83niVWmMU1VdHzG1CyfI2VS7f7nZltnKtHcg20hW+7Uo5GfK4MeDPoU3qI8EA==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/utils/-/utils-8.67.0.tgz",
"integrity": "sha512-U9D1FdwEWBwok3hxxSdhclMb0twvt9QnjIQ0VfQ1AiX2epnpSgv2ubVDsayOFyY8K6FX+AQ7E0FKWVG3iKsj1A==",
"dev": true,
"license": "MIT",
"dependencies": {
"@eslint-community/eslint-utils": "^4.9.1",
"@typescript-eslint/scope-manager": "8.66.0",
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/typescript-estree": "8.66.0"
"@typescript-eslint/scope-manager": "8.67.0",
"@typescript-eslint/types": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
@@ -1272,13 +1272,13 @@
}
},
"node_modules/@typescript-eslint/visitor-keys": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.66.0.tgz",
"integrity": "sha512-dkKR8q+lKciskj1Y3vthHktl+3cMLWGyVUP23bRiPZ5O9BRT++4EqDDV+TVeIKBL1VXVEqrJlz8MYbcnvJcAlg==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/@typescript-eslint/visitor-keys/-/visitor-keys-8.67.0.tgz",
"integrity": "sha512-fkv8dHRDqfGtTHuJeebdrQ7cX6Ad4WAS00rgHh9UGvMycF1mjBfsxry1XsLIFhWZ6Judlh6UdzK+TYlbpCXgnA==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/types": "8.66.0",
"@typescript-eslint/types": "8.67.0",
"eslint-visitor-keys": "^5.0.0"
},
"engines": {
@@ -2053,9 +2053,9 @@
}
},
"node_modules/globals": {
"version": "17.9.0",
"resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz",
"integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==",
"version": "17.10.0",
"resolved": "https://registry.npmjs.org/globals/-/globals-17.10.0.tgz",
"integrity": "sha512-V0kztuWST2k8A/VbxAY8+L+7+Rgo3fyA24IHRLrZp7HOzJjV0gHSaZUjK9lpP/IrBSNite2tZ1prhRkinRu1CA==",
"dev": true,
"license": "MIT",
"engines": {
@@ -2709,9 +2709,9 @@
}
},
"node_modules/oxfmt": {
"version": "0.62.0",
"resolved": "https://registry.npmjs.org/oxfmt/-/oxfmt-0.62.0.tgz",
"integrity": "sha512-vxgGHTmnDU9j4CX7dDBLzxgmHxfda/yPcgJkGCMUSCwRmz+euo/V08xXLNgXTeqAB9Fhf3Pe2nO1RNKLCVgphQ==",
"version": "0.63.0",
"resolved": "https://registry.npmjs.org/oxfmt/-/oxfmt-0.63.0.tgz",
"integrity": "sha512-kgdDwv35wvVf6554U2Ab8Jnd0zTM+TsEQWwaB70RAjK3gICFAFGO+2Hd3Be27GMoXj3XRL9IKSNRVl7KBQL6iw==",
"dev": true,
"license": "MIT",
"dependencies": {
@@ -2727,25 +2727,25 @@
"url": "https://github.com/sponsors/Boshen"
},
"optionalDependencies": {
"@oxfmt/binding-android-arm-eabi": "0.62.0",
"@oxfmt/binding-android-arm64": "0.62.0",
"@oxfmt/binding-darwin-arm64": "0.62.0",
"@oxfmt/binding-darwin-x64": "0.62.0",
"@oxfmt/binding-freebsd-x64": "0.62.0",
"@oxfmt/binding-linux-arm-gnueabihf": "0.62.0",
"@oxfmt/binding-linux-arm-musleabihf": "0.62.0",
"@oxfmt/binding-linux-arm64-gnu": "0.62.0",
"@oxfmt/binding-linux-arm64-musl": "0.62.0",
"@oxfmt/binding-linux-ppc64-gnu": "0.62.0",
"@oxfmt/binding-linux-riscv64-gnu": "0.62.0",
"@oxfmt/binding-linux-riscv64-musl": "0.62.0",
"@oxfmt/binding-linux-s390x-gnu": "0.62.0",
"@oxfmt/binding-linux-x64-gnu": "0.62.0",
"@oxfmt/binding-linux-x64-musl": "0.62.0",
"@oxfmt/binding-openharmony-arm64": "0.62.0",
"@oxfmt/binding-win32-arm64-msvc": "0.62.0",
"@oxfmt/binding-win32-ia32-msvc": "0.62.0",
"@oxfmt/binding-win32-x64-msvc": "0.62.0"
"@oxfmt/binding-android-arm-eabi": "0.63.0",
"@oxfmt/binding-android-arm64": "0.63.0",
"@oxfmt/binding-darwin-arm64": "0.63.0",
"@oxfmt/binding-darwin-x64": "0.63.0",
"@oxfmt/binding-freebsd-x64": "0.63.0",
"@oxfmt/binding-linux-arm-gnueabihf": "0.63.0",
"@oxfmt/binding-linux-arm-musleabihf": "0.63.0",
"@oxfmt/binding-linux-arm64-gnu": "0.63.0",
"@oxfmt/binding-linux-arm64-musl": "0.63.0",
"@oxfmt/binding-linux-ppc64-gnu": "0.63.0",
"@oxfmt/binding-linux-riscv64-gnu": "0.63.0",
"@oxfmt/binding-linux-riscv64-musl": "0.63.0",
"@oxfmt/binding-linux-s390x-gnu": "0.63.0",
"@oxfmt/binding-linux-x64-gnu": "0.63.0",
"@oxfmt/binding-linux-x64-musl": "0.63.0",
"@oxfmt/binding-openharmony-arm64": "0.63.0",
"@oxfmt/binding-win32-arm64-msvc": "0.63.0",
"@oxfmt/binding-win32-ia32-msvc": "0.63.0",
"@oxfmt/binding-win32-x64-msvc": "0.63.0"
},
"peerDependencies": {
"svelte": "^5.0.0",
@@ -3211,16 +3211,16 @@
}
},
"node_modules/typescript-eslint": {
"version": "8.66.0",
"resolved": "https://registry.npmjs.org/typescript-eslint/-/typescript-eslint-8.66.0.tgz",
"integrity": "sha512-QlEbBPz/RuJ1XUHj29nm3t0F/O/cSlEnntozqPOYHnnTGAXFamnMBu5i9Vn6vhUPHGAjR+Vl+5J8vPN/BMUrJw==",
"version": "8.67.0",
"resolved": "https://registry.npmjs.org/typescript-eslint/-/typescript-eslint-8.67.0.tgz",
"integrity": "sha512-S2udFs8tCKEKffuJ4TB1idGUZiXdCPGi3IPBGWXarbLQ5UPXORV8QEVzJ4gCRduURMb5EkpNCdjbk0eDIuI8Yg==",
"dev": true,
"license": "MIT",
"dependencies": {
"@typescript-eslint/eslint-plugin": "8.66.0",
"@typescript-eslint/parser": "8.66.0",
"@typescript-eslint/typescript-estree": "8.66.0",
"@typescript-eslint/utils": "8.66.0"
"@typescript-eslint/eslint-plugin": "8.67.0",
"@typescript-eslint/parser": "8.67.0",
"@typescript-eslint/typescript-estree": "8.67.0",
"@typescript-eslint/utils": "8.67.0"
},
"engines": {
"node": "^18.18.0 || ^20.9.0 || >=21.1.0"
+5 -5
View File
@@ -32,15 +32,15 @@
"@types/lodash-es": "^4.17.12",
"@types/node": "^26.2.0",
"@types/ws": "^8.18.1",
"@typescript-eslint/eslint-plugin": "^8.65.0",
"@typescript-eslint/parser": "^8.66.0",
"@typescript-eslint/eslint-plugin": "^8.67.0",
"@typescript-eslint/parser": "^8.67.0",
"eslint": "^10.8.1",
"eslint-config-prettier": "^10.1.8",
"globals": "^17.9.0",
"oxfmt": "^0.62.0",
"globals": "^17.10.0",
"oxfmt": "^0.63.0",
"tscw-config": "^1.1.2",
"typescript": "^6.0.3",
"typescript-eslint": "^8.66.0",
"typescript-eslint": "^8.67.0",
"vitest": "^4.1.10"
},
"engines": {
+10 -1
View File
@@ -21,7 +21,7 @@ from functools import partial
from typing import cast
from uuid import UUID
from superset import db
from superset import db, security_manager
from superset.commands.base import BaseCommand
from superset.commands.database.exceptions import DatabaseNotFoundError
from superset.daos.database import DatabaseUserOAuth2TokensDAO
@@ -31,6 +31,7 @@ from superset.exceptions import OAuth2Error
from superset.key_value.types import JsonKeyValueCodec, KeyValueResource
from superset.models.core import Database, DatabaseUserOAuth2Tokens
from superset.superset_typing import OAuth2State
from superset.utils.core import get_user_id
from superset.utils.decorators import on_error, transaction
from superset.utils.oauth2 import decode_oauth2_state
@@ -121,6 +122,14 @@ class OAuth2StoreTokenCommand(BaseCommand):
self._state = decode_oauth2_state(self._parameters["state"])
# Bind the callback to the current session: require an authenticated,
# non-guest user whose id matches the one carried in the state.
user_id = get_user_id()
if user_id is None or security_manager.is_guest_user():
raise OAuth2Error("The OAuth2 callback requires an authenticated user")
if user_id != self._state["user_id"]:
raise OAuth2Error("The OAuth2 state belongs to a different user")
if database := DatabaseUserOAuth2TokensDAO.get_database(
self._state["database_id"]
):
@@ -15,9 +15,12 @@
# specific language governing permissions and limitations
# under the License.
import gzip
import ipaddress
import logging
import os
import re
import socket
from http.client import HTTPConnection, HTTPResponse, HTTPSConnection
from typing import Any
from urllib import request
from urllib.parse import urljoin, urlparse
@@ -47,7 +50,7 @@ from superset.models.helpers import ChildMultipleResultsFound
from superset.sql.parse import Table
from superset.utils import json
from superset.utils.core import get_user
from superset.utils.network import is_safe_host
from superset.utils.network import is_safe_host, is_safe_ip
logger = logging.getLogger(__name__)
@@ -76,6 +79,47 @@ class _ValidatingRedirectHandler(HTTPRedirectHandler):
return super().redirect_request(req, fp, code, msg, headers, newurl)
def _raise_for_unsafe_peer(sock: socket.socket) -> None:
"""
Validate that an established connection's actual peer is publicly
routable, so the address reached matches the policy applied to the host.
"""
peer = sock.getpeername()[0]
if not is_safe_ip(ipaddress.ip_address(peer)):
raise DatasetForbiddenDataURI()
class _PeerValidatingHTTPConnection(HTTPConnection):
"""HTTP connection that validates the peer address on connect."""
def connect(self) -> None:
super().connect()
_raise_for_unsafe_peer(self.sock)
class _PeerValidatingHTTPSConnection(HTTPSConnection):
"""HTTPS connection that validates the peer address after the handshake."""
def connect(self) -> None:
super().connect()
_raise_for_unsafe_peer(self.sock)
class _PeerValidatingHTTPHandler(request.HTTPHandler):
"""Opens HTTP connections through the peer-validating connection class."""
def http_open(self, req: request.Request) -> HTTPResponse:
return self.do_open(_PeerValidatingHTTPConnection, req)
class _PeerValidatingHTTPSHandler(request.HTTPSHandler):
"""Opens HTTPS connections through the peer-validating connection class."""
def https_open(self, req: request.Request) -> HTTPResponse:
context = self._context # type: ignore[attr-defined]
return self.do_open(_PeerValidatingHTTPSConnection, req, context=context)
CHUNKSIZE = 512
VARCHAR = re.compile(r"VARCHAR\((\d+)\)", re.IGNORECASE)
@@ -581,7 +625,17 @@ def load_data(data_uri: str, dataset: SqlaTable, database: Database) -> None:
validate_data_uri(data_uri)
logger.info("Downloading data from %s", data_uri)
opener = request.build_opener(_ValidatingRedirectHandler)
handlers: list[request.BaseHandler | type[request.BaseHandler]] = [
_ValidatingRedirectHandler
]
if not app.config["DATASET_IMPORT_ALLOW_INTERNAL_DATA_URLS"]:
# Also enforce the policy at the socket layer: re-check the peer of
# every connection, including each redirect hop. Disable proxies so the
# connection is made directly to the destination and the peer check
# validates the destination address rather than a proxy's.
handlers.append(request.ProxyHandler({}))
handlers.extend([_PeerValidatingHTTPHandler, _PeerValidatingHTTPSHandler])
opener = request.build_opener(*handlers)
data = opener.open(data_uri) # pylint: disable=consider-using-with # noqa: S310
if data_uri.endswith(".gz"):
data = gzip.open(data)
+72 -6
View File
@@ -137,6 +137,29 @@ def resolve_executor_user(model: ReportSchedule) -> tuple["User", str]:
return user, username
def _should_build_execution_context(model: ReportSchedule) -> bool:
"""
Whether an execution should run under a :class:`ReportExecutionContext`.
Reports always do their behavior is unchanged. Alerts join them only when
they deliver a rendered PNG/PDF screenshot to recipients, which happens when
``ALERTS_ATTACH_REPORTS`` is enabled. Delivered screenshots must fail closed:
the context selects the fail-closed readiness predicate and disables
partial-tile fallback, so a blank or incomplete capture raises instead of
being delivered.
CSV/text alerts, alerts without the attach flag, the non-delivered
query-context capture, and UI thumbnails are deliberately excluded and keep
their lenient capture contract.
"""
if model.type == ReportScheduleType.REPORT:
return True
return model.report_format in (
ReportDataFormat.PNG,
ReportDataFormat.PDF,
) and feature_flag_manager.is_feature_enabled("ALERTS_ATTACH_REPORTS")
def log_report_delivery_phase(
report_context: ReportExecutionContext | None,
recipient_type: ReportRecipientType | None,
@@ -1972,13 +1995,13 @@ class ReportSuccessState(BaseReportState):
try:
self.send()
except Exception as ex: # pylint: disable=broad-except
if self._handle_retry_or_error(str(ex), ex):
except Exception as first_ex: # pylint: disable=broad-except
if self._handle_retry_or_error(str(first_ex), first_ex):
return # retry scheduled — exit cleanly
try:
self.update_report_schedule_and_log(
ReportState.ERROR, error_message=str(ex)
ReportState.ERROR, error_message=str(first_ex)
)
except (ReportScheduleUnexpectedError, SQLAlchemyError) as logging_ex:
# Logging failed (likely StaleDataError), but we still want to
@@ -1991,7 +2014,45 @@ class ReportSuccessState(BaseReportState):
exc_info=True,
)
# Re-raise the original exception, not the logging failure
raise ex from logging_ex
raise first_ex from logging_ex
# A delivery failure from the Success/Grace path must notify the
# owner just like the first-run path (ReportNotTriggeredErrorState).
# Without this, a schedule whose previous run succeeded would fail
# silently — e.g. once a screenshot capture starts failing closed.
# The error grace period still throttles repeated notifications.
if not self.is_in_error_grace_period():
second_error_message = REPORT_SCHEDULE_ERROR_NOTIFICATION_MARKER
try:
self.send_error(
f"Error occurred for {self._report_schedule.type}:"
f" {self._report_schedule.name}",
str(first_ex),
)
except SupersetErrorsException as second_ex:
second_error_message = ";".join(
[error.message for error in second_ex.errors]
)
except ReportScheduleUnexpectedError:
# send_error failed due to logging issue; log and continue
# to raise the original error
logger.warning(
"Failed to send error notification due to database issue",
exc_info=True,
)
except Exception as second_ex: # pylint: disable=broad-except
second_error_message = str(second_ex)
finally:
try:
self.update_report_schedule_and_log(
ReportState.ERROR, error_message=second_error_message
)
except ReportScheduleUnexpectedError:
# Logging failed again; log it but don't hide first_ex
logger.warning(
"Failed to log final error state due to database issue",
exc_info=True,
)
raise
# send() succeeded — clear retry state and log success. Any execution
@@ -2058,13 +2119,18 @@ class AsyncExecuteReportScheduleCommand(BaseCommand):
if not self._model:
raise ReportScheduleExecuteUnexpectedError()
if self._model.type == ReportScheduleType.REPORT:
# Reports always run under an execution context; alerts join them
# only when they deliver a rendered screenshot, so a blank/partial
# capture fails closed instead of being delivered. Ownership and
# terminal-error persistence remain report-only recovery semantics.
if _should_build_execution_context(self._model):
# An invocation that enters on WORKING is a duplicate or stale
# recovery, not the owner that created the active row. Its state
# handler may terminalize a stale execution, but the command
# boundary must never infer ownership from a replayed UUID.
owns_report_working_state = (
self._model.last_state != ReportState.WORKING
self._model.type == ReportScheduleType.REPORT
and self._model.last_state != ReportState.WORKING
)
total_seconds = resolve_report_execution_budget_seconds(
app.config,
+46 -1
View File
@@ -58,6 +58,7 @@ from superset.utils.core import (
get_column_name,
get_column_names_from_columns,
get_column_names_from_metrics,
get_user_id,
is_adhoc_column,
is_adhoc_metric,
)
@@ -270,6 +271,11 @@ class QueryContextProcessor:
datasource = self._qc_datasource
extra_cache_keys = datasource.get_extra_cache_keys(query_obj.to_dict())
# Annotation data is cached on the same entry as the dataframe, so the
# key must also bind the annotation sources' security context.
if query_obj and query_obj.annotation_layers:
kwargs["annotation_context"] = self._annotation_cache_context(query_obj)
cache_key = (
query_obj.cache_key(
datasource=datasource.uid,
@@ -283,6 +289,32 @@ class QueryContextProcessor:
)
return cache_key
def _annotation_cache_context(self, query_obj: QueryObject) -> dict[str, Any]:
"""
Cache-key material binding cached annotation data to its security
context.
Annotation payloads are fetched per requesting user and stored on the
same cache entry as the dataframe, so the key also binds the requesting
user and, for chart-backed layers, the RLS clauses of the referenced
chart's datasource.
"""
source_rls: dict[str, list[str] | None] = {}
for layer in query_obj.annotation_layers:
if layer.get("sourceType") not in ("line", "table"):
continue
layer_value = layer.get("value")
chart = (
ChartDAO.find_by_id(layer_value) if layer_value is not None else None
)
annotation_datasource = chart.datasource if chart else None
source_rls[str(layer.get("value"))] = (
security_manager.get_rls_cache_key(annotation_datasource)
if annotation_datasource
else None
)
return {"user_id": get_user_id(), "source_rls": source_rls}
def get_query_result(self, query_object: QueryObject) -> QueryResult:
"""
Returns a pandas dataframe based on the query object.
@@ -636,6 +668,11 @@ class QueryContextProcessor:
if layer["sourceType"] == "NATIVE"
]
layer_ids = [layer["value"] for layer in annotation_layers]
# Enforce the annotation read permission before returning layer records.
if layer_ids and not security_manager.can_access("can_read", "Annotation"):
raise QueryObjectValidationError(
_("You don't have access to annotation layers")
)
layer_objects = {
layer_object.id: layer_object
for layer_object in AnnotationLayerDAO.find_by_ids(layer_ids)
@@ -645,6 +682,15 @@ class QueryContextProcessor:
for layer in annotation_layers:
layer_id = layer["value"]
layer_name = layer["name"]
# A request may reference a layer id that does not exist; treat it
# as a validation error rather than failing on the missing key.
if (layer_object := layer_objects.get(layer_id)) is None:
raise QueryObjectValidationError(
_(
"Annotation layer with ID %(layer_id)s was not found",
layer_id=layer_id,
)
)
columns = [
"start_dttm",
"end_dttm",
@@ -652,7 +698,6 @@ class QueryContextProcessor:
"long_descr",
"json_metadata",
]
layer_object = layer_objects[layer_id]
records = [
{column: getattr(annotation, column) for column in columns}
for annotation in layer_object.annotation
+7 -1
View File
@@ -957,7 +957,13 @@ class AnnotationDatasource(BaseDatasource):
def get_query_str(self, query_obj: QueryObjectDict) -> str:
raise NotImplementedError()
def values_for_column(self, column_name: str, limit: int = 10000) -> list[Any]:
def values_for_column(
self,
column_name: str,
limit: int = 10000,
denormalize_column: bool = False,
array_elements: bool = False,
) -> list[Any]:
raise NotImplementedError()
+2 -1
View File
@@ -418,7 +418,8 @@ class DashboardRestApi(
result:
type: array
items:
type: object
$ref: >-
#/components/schemas/{{self.__class__.__name__}}.get_list
400:
$ref: '#/components/responses/400'
401:
+5
View File
@@ -133,6 +133,9 @@ class DatasourceRestApi(BaseSupersetApi):
row_limit = apply_max_row_limit(app.config["FILTER_SELECT_ROW_LIMIT"])
denormalize_column = not datasource.normalize_columns
# Element-level operators (Contains any / Contains all) request the
# distinct array *elements* rather than distinct whole arrays.
array_elements = parse_boolean_string(request.args.get("array_elements"))
# Cache distinct column-value results so a dashboard with many filters
# backed by the same (often heavy) virtual dataset doesn't re-execute
@@ -165,6 +168,7 @@ class DatasourceRestApi(BaseSupersetApi):
"col": column_name,
"limit": row_limit,
"denorm": denormalize_column,
"elements": array_elements,
"rls": security_manager.get_rls_cache_key(datasource),
"changed_on": str(getattr(datasource, "changed_on", "")),
},
@@ -189,6 +193,7 @@ class DatasourceRestApi(BaseSupersetApi):
column_name=column_name,
limit=row_limit,
denormalize_column=denormalize_column,
array_elements=array_elements,
)
except KeyError:
return self.response(
+4 -4
View File
@@ -83,7 +83,7 @@ The tables below (generated via `python superset/db_engine_specs/lib.py`) summar
| Databricks (legacy) | 70 | Supported | Partial | Supported | Partial | Partial | Not supported |
| StarRocks | 69 | Supported | Partial | Supported | Partial | Partial | Partial |
| SingleStore | 68 | Supported | Partial | Supported | Not supported | Partial | Not supported |
| ClickHouse Connect (Superset) | 61 | Supported | Partial | Partial | Partial | Partial | Not supported |
| ClickHouse Connect (Superset) | 62 | Supported | Partial | Supported | Partial | Partial | Not supported |
| Google Sheets | 61 | Supported | Partial | Supported | Supported | Partial | Partial |
| Aurora MySQL (Data API) | 59 | Supported | Partial | Supported | Partial | Partial | Not supported |
| MariaDB | 59 | Supported | Partial | Supported | Partial | Partial | Not supported |
@@ -91,7 +91,7 @@ The tables below (generated via `python superset/db_engine_specs/lib.py`) summar
| OceanBase | 59 | Supported | Partial | Supported | Partial | Partial | Not supported |
| MotherDuck | 58 | Supported | Partial | Supported | Not supported | Partial | Not supported |
| KustoSQL | 54 | Supported | Partial | Supported | Partial | Partial | Not supported |
| ClickHouse | 51 | Supported | Partial | Partial | Partial | Partial | Not supported |
| ClickHouse | 52 | Supported | Partial | Supported | Partial | Partial | Not supported |
| Databend | 51 | Supported | Partial | Supported | Partial | Partial | Not supported |
| Apache Drill | 50 | Supported | Partial | Supported | Partial | Partial | Partial |
| Apache Druid | 47 | Partial | Partial | Supported | Partial | Partial | Not supported |
@@ -293,8 +293,8 @@ The tables below (generated via `python superset/db_engine_specs/lib.py`) summar
| Aurora MySQL (Data API) | True | True | True | True | True | True | True | True |
| Aurora PostgreSQL (Data API) | True | True | True | True | True | True | True | True |
| Azure Synapse | True | True | True | True | True | True | True | True |
| ClickHouse | False | True | True | True | True | True | True | True |
| ClickHouse Connect (Superset) | False | True | True | True | True | True | True | True |
| ClickHouse | True | True | True | True | True | True | True | True |
| ClickHouse Connect (Superset) | True | True | True | True | True | True | True | True |
| CockroachDB | True | True | True | True | True | True | True | True |
| Couchbase | True | True | True | True | False | True | True | True |
| CrateDB | True | True | True | True | True | True | True | True |
+119 -9
View File
@@ -55,7 +55,13 @@ from sqlalchemy.engine.reflection import Inspector
from sqlalchemy.engine.url import URL
from sqlalchemy.ext.compiler import compiles
from sqlalchemy.sql import literal_column, quoted_name, text
from sqlalchemy.sql.expression import BinaryExpression, ColumnClause, Select, TextClause
from sqlalchemy.sql.expression import (
BinaryExpression,
ColumnClause,
ColumnElement,
Select,
TextClause,
)
from sqlalchemy.types import TypeEngine
from superset import db
@@ -528,6 +534,11 @@ class BaseEngineSpec: # pylint: disable=too-many-public-methods
time_groupby_inline = False
limit_method = LimitMethod.FORCE_LIMIT
supports_multivalues_insert = False
# Whether this engine supports first-class multi-value (array-typed) columns.
# When True, array columns are classified as ``GenericDataType.MULTI_VALUE`` and
# the ``array_*`` capability methods below must be implemented. Defaults to
# False so engines that have not opted in keep treating arrays as strings.
supports_multivalue_columns = False
allows_joins = True
allows_subqueries = True
allows_alias_in_select = True
@@ -1340,12 +1351,12 @@ class BaseEngineSpec: # pylint: disable=too-many-public-methods
return cursor.fetchmany(limit)
data = cursor.fetchall()
description = cursor.description or []
# Create a mapping between column index and a mutator function to normalize
# values with. The first two items in the description row are the column
# name and type.
# Create a mapping between column name and a mutator function to normalize
# values with. The first two items in the description row are
# the column name and type.
column_mutators = {
index: func
for index, row in enumerate(description)
row[0]: func
for row in description
if (
func := cls.column_type_mutators.get(
type(cls.get_sqla_column_type(cls.get_datatype(row[1])))
@@ -1353,11 +1364,11 @@ class BaseEngineSpec: # pylint: disable=too-many-public-methods
)
}
if column_mutators:
if not isinstance(data, list):
data = list(data)
indexes = {row[0]: idx for idx, row in enumerate(description)}
for row_idx, row in enumerate(data):
new_row = list(row)
for col_idx, func in column_mutators.items():
for col, func in column_mutators.items():
col_idx = indexes[col]
new_row[col_idx] = func(row[col_idx])
data[row_idx] = tuple(new_row)
@@ -2571,6 +2582,105 @@ class BaseEngineSpec: # pylint: disable=too-many-public-methods
logger.error(ex, exc_info=True)
raise
@classmethod
def array_contains_any(cls, col: ColumnElement, values: list[Any]) -> ColumnElement:
"""
Build a boolean expression testing whether array column ``col`` contains
**any** of ``values`` (element-level membership, like ``IN``). Engines
that set ``supports_multivalue_columns = True`` must override this with
their native function (e.g. ClickHouse ``hasAny``).
:param col: SQLAlchemy column element for the array column
:param values: element values to look for inside the array
:return: a SQLAlchemy boolean expression
"""
raise NotImplementedError(
f"{cls.engine} does not support multi-value (array) columns"
)
@classmethod
def array_contains_all(cls, col: ColumnElement, values: list[Any]) -> ColumnElement:
"""
Build a boolean expression testing whether array column ``col`` contains
**all** of ``values``. Engines that set
``supports_multivalue_columns = True`` must override this with their
native function (e.g. ClickHouse ``hasAll``).
:param col: SQLAlchemy column element for the array column
:param values: element values that must all be present
:return: a SQLAlchemy boolean expression
"""
raise NotImplementedError(
f"{cls.engine} does not support multi-value (array) columns"
)
@classmethod
def array_length(cls, col: ColumnElement) -> ColumnElement:
"""
Build a numeric expression returning the number of elements in array
column ``col``. Engines that set ``supports_multivalue_columns = True``
must override this with their native array-length function. Used both for
the ``Length`` filter and the ``Is empty`` / ``Is not empty`` operators.
:param col: SQLAlchemy column element for the array column
:return: a SQLAlchemy numeric expression
"""
raise NotImplementedError(
f"{cls.engine} does not support multi-value (array) columns"
)
@classmethod
def array_literal(cls, values: list[Any]) -> ColumnElement:
"""
Build an array-literal expression from ``values`` (e.g. ClickHouse
``array(v1, v2)`` == ``[v1, v2]``). Used for the whole-array (column-
level) operators ``=`` / ``!=`` / ``IN`` / ``NOT IN`` where the array is
compared as a single value. Engines that set
``supports_multivalue_columns = True`` must override this.
:param values: element values that make up the array
:return: a SQLAlchemy array-literal expression
"""
raise NotImplementedError(
f"{cls.engine} does not support multi-value (array) columns"
)
@classmethod
def array_explode(cls, col: ColumnElement) -> ColumnElement:
"""
Build an expression that expands array column ``col`` into one row per
element (e.g. ClickHouse ``arrayJoin``). Used to source **element-level**
value suggestions (``SELECT DISTINCT array_explode(col)``) for the
``Contains any`` / ``Contains all`` filter operators, so the picker offers
individual elements rather than whole arrays. Engines that set
``supports_multivalue_columns = True`` must override this.
:param col: SQLAlchemy column element for the array column
:return: a SQLAlchemy expression yielding one element per row
"""
raise NotImplementedError(
f"{cls.engine} does not support multi-value (array) columns"
)
@classmethod
def get_array_element_type( # pylint: disable=unused-argument
cls, native_type: str | None
) -> GenericDataType | None:
"""
Return the generic type of an array column's **element** type, derived
from its native type string (e.g. ClickHouse ``Array(Int32)`` ->
``NUMERIC``), or ``None`` when the engine has no array support or the
element type cannot be resolved.
Callers use this to coerce filter values to the element type before
building array expressions, so, for example, a ``Contains any`` filter on
a numeric array compares against numbers rather than quoted strings.
:param native_type: native column type string of the array column
:return: the element's :class:`GenericDataType`, or ``None``
"""
return None
@classmethod
def get_column_spec( # pylint: disable=unused-argument
cls,
+63 -4
View File
@@ -26,8 +26,9 @@ from flask import current_app as app
from flask_babel import gettext as __
from marshmallow import fields, Schema
from marshmallow.validate import Range
from sqlalchemy import types
from sqlalchemy import func, types
from sqlalchemy.engine.url import URL
from sqlalchemy.sql.expression import ColumnElement
from urllib3.exceptions import NewConnectionError
from superset.databases.utils import make_url_safe
@@ -55,6 +56,7 @@ class ClickHouseBaseEngineSpec(BaseEngineSpec):
time_groupby_inline = True
supports_multivalues_insert = True
supports_multivalue_columns = True
# ClickHouse doesn't support IS true/false syntax, use = true/false instead
use_equality_for_boolean_filters = True
@@ -112,6 +114,7 @@ class ClickHouseBaseEngineSpec(BaseEngineSpec):
_time_grain_expressions = {
None: "{col}",
"PT1S": "toStartOfSecond(toDateTime64({col}, 3))",
"PT1M": "toStartOfMinute(toDateTime({col}))",
"PT5M": "toDateTime(intDiv(toUInt32(toDateTime({col})), 300)*300)",
"PT10M": "toDateTime(intDiv(toUInt32(toDateTime({col})), 600)*600)",
@@ -127,12 +130,18 @@ class ClickHouseBaseEngineSpec(BaseEngineSpec):
column_type_mappings = (
(
re.compile(r".*Enum.*", re.IGNORECASE),
# Anchor to the start so only top-level arrays match. This must be
# ordered before the ``Enum`` entry below: ``Array(Enum8(...))`` is a
# real array and should classify as MULTI_VALUE, not STRING. The
# anchor also prevents over-matching nested arrays such as
# ``Map(String, Array(String))`` or ``Tuple(Array(String))``, which
# are not themselves array columns and must keep their own type.
re.compile(r"^Array\(", re.IGNORECASE),
types.String(),
GenericDataType.STRING,
GenericDataType.MULTI_VALUE,
),
(
re.compile(r".*Array.*", re.IGNORECASE),
re.compile(r".*Enum.*", re.IGNORECASE),
types.String(),
GenericDataType.STRING,
),
@@ -173,6 +182,56 @@ class ClickHouseBaseEngineSpec(BaseEngineSpec):
),
)
@classmethod
def array_contains_any(cls, col: ColumnElement, values: list[Any]) -> ColumnElement:
# ClickHouse: hasAny(arr, [v1, v2]) -> 1 if arr shares any element.
# func.array(*values) renders as array(v1, v2) == [v1, v2].
return func.hasAny(col, func.array(*values))
@classmethod
def array_contains_all(cls, col: ColumnElement, values: list[Any]) -> ColumnElement:
# ClickHouse: hasAll(arr, [v1, v2]) -> 1 if arr contains all elements.
return func.hasAll(col, func.array(*values))
@classmethod
def array_length(cls, col: ColumnElement) -> ColumnElement:
# ClickHouse: length(arr) -> number of elements
return func.length(col)
@classmethod
def array_literal(cls, values: list[Any]) -> ColumnElement:
# ClickHouse: array(v1, v2) is equivalent to the literal [v1, v2].
return func.array(*values)
@classmethod
def array_explode(cls, col: ColumnElement) -> ColumnElement:
# ClickHouse: arrayJoin(arr) yields one row per element, so
# SELECT DISTINCT arrayJoin(arr) returns the distinct elements.
return func.arrayJoin(col)
# Matches the element type inside a top-level ``Array(...)`` column, e.g.
# ``Array(Int32)`` -> ``Int32``, ``Array(Nullable(String))`` -> ``String``.
_ARRAY_ELEMENT_RE = re.compile(r"^Array\((?P<inner>.+)\)$", re.IGNORECASE)
# Element-type wrappers that don't change the underlying generic type.
_ELEMENT_WRAPPER_RE = re.compile(
r"^(?:Nullable|LowCardinality)\((?P<inner>.+)\)$", re.IGNORECASE
)
@classmethod
def get_array_element_type(cls, native_type: str | None) -> GenericDataType | None:
if not native_type:
return None
match = cls._ARRAY_ELEMENT_RE.match(native_type.strip())
if not match:
return None
inner = match.group("inner").strip()
# Peel wrappers (Nullable/LowCardinality) that don't alter the generic
# type so the inner scalar type drives classification.
while wrapper := cls._ELEMENT_WRAPPER_RE.match(inner):
inner = wrapper.group("inner").strip()
spec = cls.get_column_spec(inner)
return spec.generic_type if spec else None
@classmethod
def epoch_to_dttm(cls) -> str:
return "{col}"
+14 -56
View File
@@ -249,43 +249,6 @@ class MySQLEngineSpec(BasicParametersMixin, BaseEngineSpec):
types.VARCHAR(),
GenericDataType.STRING,
),
# wire-protocol FIELD_TYPE names emitted by `get_datatype`, seen on
# SQL Lab and virtual dataset columns instead of DDL type names
(
re.compile(r"^newdecimal", re.IGNORECASE),
DECIMAL(),
GenericDataType.NUMERIC,
),
(
re.compile(r"^tiny$", re.IGNORECASE),
TINYINT(),
GenericDataType.NUMERIC,
),
(
re.compile(r"^short$", re.IGNORECASE),
types.SmallInteger(),
GenericDataType.NUMERIC,
),
(
re.compile(r"^(blob|text)$", re.IGNORECASE),
types.String(),
GenericDataType.STRING,
),
(
re.compile(r"^year$", re.IGNORECASE),
types.Integer(),
GenericDataType.NUMERIC,
),
(
re.compile(r"^enum\b", re.IGNORECASE),
types.String(),
GenericDataType.STRING,
),
(
re.compile(r"^set\b", re.IGNORECASE),
types.String(),
GenericDataType.STRING,
),
)
column_type_mutators: dict[types.TypeEngine, Callable[[Any], Any]] = {
DECIMAL: lambda val: Decimal(val) if isinstance(val, str) else val
@@ -444,27 +407,22 @@ class MySQLEngineSpec(BasicParametersMixin, BaseEngineSpec):
@classmethod
def get_datatype(cls, type_code: Any) -> Optional[str]:
if not cls.type_code_map:
# only import and store if needed at least once
# pylint: disable=import-outside-toplevel
try:
import MySQLdb
mysql_module = MySQLdb
except ImportError:
mysql_module = __import__("pymysql")
ft = mysql_module.constants.FIELD_TYPE
cls.type_code_map = {
getattr(ft, k): k for k in dir(ft) if not k.startswith("_")
}
datatype = type_code
if isinstance(type_code, int):
if not cls.type_code_map:
# only import and store if needed at least once
# pylint: disable=import-outside-toplevel
try:
import MySQLdb
ft = MySQLdb.constants.FIELD_TYPE
except ImportError:
try:
import pymysql # type: ignore[import-untyped]
ft = pymysql.constants.FIELD_TYPE
except ImportError:
from mysql.connector.constants import FieldType
ft = FieldType
cls.type_code_map = {
getattr(ft, k): k for k in dir(ft) if not k.startswith("_")
}
datatype = cls.type_code_map.get(type_code)
if datatype and isinstance(datatype, str) and datatype:
return datatype
+6 -2
View File
@@ -26,8 +26,12 @@ if TYPE_CHECKING:
# Matches only the static asset endpoint:
# /api/v1/extensions/<publisher>/<name>/<path:file>, where the file portion may
# contain nested segments (worker / WASM / chunk subfolders).
# Does not match the list (/), get (/<publisher>/<name>), or info (/_info) endpoints.
_ASSET_PATH_RE: re.Pattern[str] = re.compile(r"^/api/v1/extensions/[^/]+/[^/]+/.+$")
# Does not match the list (/), get (/<publisher>/<name>), or info (/_info)
# endpoints, nor the per-user storage endpoints under
# /<publisher>/<name>/storage/, whose responses must keep ``Vary: Cookie``.
_ASSET_PATH_RE: re.Pattern[str] = re.compile(
r"^/api/v1/extensions/[^/]+/[^/]+/(?!storage/).+$"
)
class ExtensionCacheMiddleware:
+8 -2
View File
@@ -92,10 +92,16 @@ class ExtensionStorageRestApi(BaseApi):
route_base = "/api/v1/extensions"
def response(self, status_code: int, **kwargs: Any) -> Response:
"""Helper method to create JSON responses."""
"""Helper method to create JSON responses.
Stored values are scoped to the requesting user, so responses are
marked non-cacheable.
"""
from flask import jsonify
return jsonify(kwargs), status_code
response = jsonify(kwargs)
response.cache_control.no_store = True
return response, status_code
def response_404(self, message: str = "Not found") -> Response:
"""Helper method to create 404 responses."""
+36 -2
View File
@@ -1272,6 +1272,34 @@ def get_dataset_id_from_context(metric_key: str) -> int:
raise SupersetTemplateException(exc_message)
def guest_user_can_access_dataset(dataset: SqlaTable) -> bool:
"""
Whether the current guest (embedded) user may read the given dataset.
Guest access is granted per dashboard, so the dataset must back at least
one chart on a dashboard the guest token covers; a ``datasets`` allowlist
on the token further restricts the reachable IDs.
:param dataset: a dataset resolved without the DAO base filter.
:returns: whether the guest user may read the dataset.
"""
guest_user = security_manager.get_current_guest_user_if_guest()
if not guest_user:
return False
allowed_datasets: list[int] | None = guest_user.guest_token.get("datasets")
if allowed_datasets is not None and (
not isinstance(allowed_datasets, list) or dataset.id not in allowed_datasets
):
return False
return any(
security_manager.has_guest_access(dashboard)
for slc in dataset.slices
for dashboard in slc.dashboards
)
def metric_macro(
env: Environment,
context: dict[str, Any],
@@ -1294,8 +1322,9 @@ def metric_macro(
if not dataset_id:
dataset_id = get_dataset_id_from_context(metric_key)
# Embedded user access is validated at the dashboard level, so we bypass
# the regular DAO filter for them
# Embedded (guest) user access is validated at the dashboard level, so the
# regular DAO filter is bypassed for them and dashboard-level scope is
# enforced explicitly below.
dataset = DatasetDAO.find_by_id(
dataset_id,
skip_base_filter=security_manager.is_guest_user(),
@@ -1303,6 +1332,11 @@ def metric_macro(
if not dataset:
raise DatasetNotFoundError(f"Dataset ID {dataset_id} not found.")
# With the base filter skipped, scope a guest to datasets reachable through
# a dashboard their token grants; reuse the not-found error for consistency.
if security_manager.is_guest_user() and not guest_user_can_access_dataset(dataset):
raise DatasetNotFoundError(f"Dataset ID {dataset_id} not found.")
metrics: dict[str, str] = {
metric.metric_name: metric.expression for metric in dataset.metrics
}
+75 -25
View File
@@ -68,6 +68,11 @@ from superset.mcp_service.session_scope import _mcp_session_token
from superset.mcp_service.utils.error_sanitization import (
sanitize_for_log as _sanitize_for_log,
)
from superset.security.api_key_scopes import (
get_resource_scope,
METHOD_PERMISSION_SCOPE_ACTION,
RESOURCE_SCOPE_NAME as RESOURCE_SCOPE_NAME,
)
from superset.security.guest_token import GuestUser
if TYPE_CHECKING:
@@ -126,19 +131,24 @@ class MCPNoAuthSourceError(ValueError):
# is a privileged, write-class operation and therefore requires the write
# scope. When introducing a new method permission, add it here.
_METHOD_TO_REQUIRED_SCOPE = {
"read": "superset:read",
# "get" is the read-class permission FAB registers on its security API
# views (User/Role) — those views have no can_read, so tools targeting
# them declare method_permission_name="get".
"get": "superset:read",
"write": "superset:write",
"delete": "superset:write",
# SQL execution (execute_sql, get_chart_sql) runs arbitrary queries and is
# treated as a write-class privileged operation for scope purposes.
"execute_sql_query": "superset:write",
method: f"superset:{action}"
for method, action in METHOD_PERMISSION_SCOPE_ACTION.items()
}
def _required_resource_scope(
class_permission_name: str, method_permission_name: str
) -> str | None:
"""Compute the ``superset:<resource>:<action>`` scope string for a tool.
Returns None if either the resource or the action isn't mapped — callers
must treat that as "no per-resource scope available," not as a grant;
the flat ``_METHOD_TO_REQUIRED_SCOPE`` fallback still applies in that case
(see ``_token_scope_allows``).
"""
return get_resource_scope(class_permission_name, method_permission_name)
def _get_token_scopes() -> set[str] | None:
"""Return the set of scopes on the current JWT access token, or None.
@@ -154,8 +164,13 @@ def _get_token_scopes() -> set[str] | None:
try:
access_token = get_access_token()
except Exception: # noqa: BLE001 - no JWT context for this request
return None
except Exception: # noqa: BLE001 - fail closed on token-context errors
logger.exception("Unable to resolve MCP access-token scopes")
# ``None`` means that no scoped credential was presented and enables
# legacy RBAC-only behavior. An empty set instead makes every scope
# check fail, so an unexpected context error cannot erase restrictions
# carried by a credential.
return set()
if access_token is None:
return None
@@ -167,12 +182,21 @@ def _get_token_scopes() -> set[str] | None:
return {str(s) for s in scopes}
def _token_scope_allows(method_permission_name: str) -> bool:
def _token_scope_allows(
method_permission_name: str, class_permission_name: str | None = None
) -> bool:
"""Return whether the current token's scopes permit the given method.
Back-compat: returns True (allow) when the token carries no scopes or there
is no JWT context, so deployments not using scopes keep RBAC-only behavior.
Only when the token advertises scopes is the mapped required scope enforced.
The per-resource scope (``superset:<resource>:<action>``, derived via
``_required_resource_scope``) is an ALTERNATIVE grant path alongside the
flat method scope: a token carrying either the flat scope
(e.g. ``superset:read``) or the matching per-resource scope
(e.g. ``superset:dashboard:read``) is allowed, so already-issued
flat-scoped tokens keep working unchanged.
"""
token_scopes = _get_token_scopes()
if token_scopes is None:
@@ -190,7 +214,15 @@ def _token_scope_allows(method_permission_name: str) -> bool:
method_permission_name,
)
return False
return required_scope in token_scopes
if required_scope in token_scopes:
return True
if class_permission_name is not None:
resource_scope = _required_resource_scope(
class_permission_name, method_permission_name
)
if resource_scope is not None and resource_scope in token_scopes:
return True
return False
class MCPPermissionDeniedError(PermissionError):
@@ -234,12 +266,20 @@ def _log_scope_denial(
cyclomatic complexity in check.
"""
required_scope = _METHOD_TO_REQUIRED_SCOPE.get(method_permission_name)
resource_scope = _required_resource_scope(
class_permission_name, method_permission_name
)
scope_desc = (
resource_scope
or required_scope
or f"unmapped method permission '{method_permission_name}'"
)
if log_denial:
logger.warning(
"Scope denied for user %s: token lacks required scope "
"'%s' for %s on %s (tool: %s)",
_sanitize_for_log(g.user.username),
required_scope,
scope_desc,
permission_str,
class_permission_name,
func.__name__,
@@ -248,7 +288,7 @@ def _log_scope_denial(
logger.debug(
"Tool hidden for user %s: token lacks required scope '%s' (tool: %s)",
_sanitize_for_log(g.user.username),
required_scope,
scope_desc,
func.__name__,
)
@@ -354,8 +394,13 @@ def check_tool_permission( # noqa: C901
)
return False
method_permission_name = getattr(func, METHOD_PERMISSION_ATTR, "read")
class_permission_name = getattr(func, CLASS_PERMISSION_ATTR, None)
# Token capabilities and user RBAC are independent restrictions.
# Disabling RBAC must not discard scopes explicitly carried by a key.
if not current_app.config.get("MCP_RBAC_ENABLED", True):
return True
return _token_scope_allows(method_permission_name, class_permission_name)
if not hasattr(g, "user") or not g.user:
if log_denial:
@@ -368,7 +413,6 @@ def check_tool_permission( # noqa: C901
)
return False
class_permission_name = getattr(func, CLASS_PERMISSION_ATTR, None)
if not class_permission_name:
# No RBAC configured for this tool; allow by default. This is a
# supported configuration (a protected tool may intentionally
@@ -382,9 +426,17 @@ def check_tool_permission( # noqa: C901
"class_permission_name; allowing access without an RBAC check",
func.__name__,
)
if not _token_scope_allows(method_permission_name):
if log_denial:
logger.warning(
"Scope denied for permission-less tool %s: token lacks "
"flat scope for method %s",
func.__name__,
method_permission_name,
)
return False
return True
method_permission_name = getattr(func, METHOD_PERMISSION_ATTR, "read")
permission_str = f"{PERMISSION_PREFIX}{method_permission_name}"
has_permission = security_manager.can_access(
@@ -399,7 +451,9 @@ def check_tool_permission( # noqa: C901
# advertises scopes. Tokens/deployments that don't use scopes (API keys,
# scope-less JWTs, dev-mode) fall through to RBAC-only behavior — see
# ``_token_scope_allows``.
if has_permission and not _token_scope_allows(method_permission_name):
if has_permission and not _token_scope_allows(
method_permission_name, class_permission_name
):
_log_scope_denial(
func,
method_permission_name,
@@ -462,7 +516,7 @@ def is_tool_visible_to_current_user(tool: Any) -> bool:
return False
if not current_app.config.get("MCP_RBAC_ENABLED", True):
return True
return check_tool_permission(tool_func, log_denial=False)
from superset.mcp_service.privacy import (
tool_requires_data_model_metadata_access,
@@ -475,10 +529,6 @@ def is_tool_visible_to_current_user(tool: Any) -> bool:
):
return False
class_permission_name = getattr(tool_func, CLASS_PERMISSION_ATTR, None)
if not class_permission_name:
return True
return check_tool_permission(tool_func, log_denial=False)
except (AttributeError, RuntimeError, ValueError):
@@ -113,15 +113,19 @@ class CompositeTokenVerifier(TokenVerifier):
)
self._api_key_prefixes = tuple(valid)
def _validate_api_key_sync(self, token: str) -> str | None:
"""Validate an API key against FAB and return the user's username.
def _validate_api_key_sync(self, token: str) -> tuple[str, list[str]] | None:
"""Validate an API key against FAB and return (username, scopes).
Runs synchronously inside a thread executor. Pushes a fresh Flask
app context so that FAB's SecurityManager can access the database.
Returns the username on success, or ``None`` if the key is invalid,
FAB does not support ``validate_api_key``, or an unexpected error
occurs (fail closed).
``scopes`` is the key's own ``ApiKey.scopes`` column, parsed from
FAB's comma-separated string storage format into a list (empty list
if the key has no scopes set, matching the "no scopes advertised"
convention used elsewhere in this module and in ``auth.py``).
Returns ``None`` if the key is invalid, FAB does not support
``validate_api_key``, or an unexpected error occurs (fail closed).
"""
if self._app is None:
return None
@@ -135,12 +139,21 @@ class CompositeTokenVerifier(TokenVerifier):
)
return None
user = sm.validate_api_key(token)
username = user.username if user else None
# Unbind the local reference so this frame no longer points at
# the raw token (defense-in-depth). Python does not zero the
# underlying string memory on rebind.
token = "" # noqa: S105
return username
if user is None:
return None
username = user.username
scopes_str = (
sm.get_api_key_scopes(token)
if hasattr(sm, "get_api_key_scopes")
else None
)
scopes = (
[s.strip() for s in scopes_str.split(",") if s.strip()]
if scopes_str
else []
)
token = "" # noqa: S105 -- unbind raw token, defense-in-depth
return username, scopes
except Exception: # noqa: BLE001 — catch-all: DB errors, FAB internals, etc.
logger.warning(
"API key transport validation failed unexpectedly; rejecting token",
@@ -168,21 +181,25 @@ class CompositeTokenVerifier(TokenVerifier):
if any(token.startswith(prefix) for prefix in self._api_key_prefixes):
if self._app is not None:
loop = asyncio.get_running_loop()
username = await loop.run_in_executor(
result = await loop.run_in_executor(
None, self._validate_api_key_sync, token
)
if username is None:
if result is None:
logger.debug(
"API key rejected at transport layer (invalid or expired)"
)
return None
username, key_scopes = result
logger.debug(
"API key validated at transport layer for user=%s", username
)
return AccessToken(
token=token,
client_id="api_key",
scopes=list(self.required_scopes or []),
# Preserve the key's own scopes exactly. An empty list
# means "no scopes advertised" and therefore retains the
# RBAC-only behavior for existing unscoped API keys.
scopes=key_scopes,
claims={
API_KEY_PASSTHROUGH_CLAIM: True,
API_KEY_VALIDATED_USERNAME_CLAIM: username,
@@ -190,10 +207,11 @@ class CompositeTokenVerifier(TokenVerifier):
)
# No app configured: fall back to prefix-only pass-through so
# ``_resolve_user_from_api_key`` handles DB validation.
# NOTE: ``MCP_REQUIRED_SCOPES`` is intentionally not enforced for
# API-key auth — FAB API keys do not carry scopes. Authorization is
# enforced downstream via ``check_tool_permission`` (RBAC).
# ``_resolve_user_from_api_key`` handles DB validation. Without an
# app there is no DB access here, so the key's own ApiKey.scopes
# cannot be read — the verifier-global required_scopes are used
# instead. Authorization is still enforced downstream via
# ``check_tool_permission`` (RBAC).
logger.debug("API key token detected (prefix match), passing through")
return AccessToken(
token=token,
+16 -1
View File
@@ -63,6 +63,7 @@ from superset.mcp_service.utils import (
sanitize_for_llm_context,
)
from superset.mcp_service.utils.response_utils import humanize_timestamp
from superset.sql.parse import has_aggregate
from superset.utils import json
@@ -386,13 +387,27 @@ class CreateDatasetMetric(BaseModel):
"""Metric definition for dataset creation."""
metric_name: str = Field(..., description="Name of the metric")
expression: str = Field(..., description="SQL expression for the metric")
expression: str = Field(
...,
description="Aggregate SQL expression for the metric, e.g. SUM(amount)",
)
verbose_name: str | None = None
description: str | None = None
metric_type: str | None = None
d3format: str | None = None
warning_text: str | None = None
@field_validator("expression")
@classmethod
def expression_must_aggregate(cls, value: str) -> str:
if not has_aggregate(value):
raise ValueError(
"saved metrics must aggregate rows; wrap a row-level column in "
"an aggregate such as MAX(column), or omit the saved metric and "
"use the dataset column directly"
)
return value
class CreateDatasetCalculatedColumn(BaseModel):
"""Calculated column definition for dataset creation."""
@@ -21,6 +21,7 @@ from typing import Any
from fastmcp import Context
from superset_core.mcp.decorators import tool, ToolAnnotations
from superset.exceptions import SupersetGenericDBErrorException
from superset.extensions import event_logger
from superset.mcp_service.dataset.schemas import (
CreateVirtualDatasetRequest,
@@ -67,14 +68,17 @@ def _cleanup_failed_dataset(dataset_id: int) -> None:
def _update_virtual_dataset(dataset_id: int, update_props: dict[str, Any]) -> Any:
from superset.commands.dataset.exceptions import DatasetUpdateFailedError
from superset.commands.dataset.exceptions import (
DatasetInvalidError,
DatasetUpdateFailedError,
)
from superset.commands.dataset.update import UpdateDatasetCommand
try:
return UpdateDatasetCommand(dataset_id, update_props).run()
except Exception as exc:
_cleanup_failed_dataset(dataset_id)
if not isinstance(exc, DatasetUpdateFailedError):
if not isinstance(exc, (DatasetInvalidError, DatasetUpdateFailedError)):
raise DatasetUpdateFailedError() from exc
raise
@@ -89,7 +93,7 @@ def _update_virtual_dataset(dataset_id: int, update_props: dict[str, Any]) -> An
destructiveHint=False,
),
)
async def create_virtual_dataset(
async def create_virtual_dataset( # noqa: C901
request: CreateVirtualDatasetRequest, ctx: Context
) -> CreateVirtualDatasetResponse:
"""Save a SQL query as a virtual dataset so it can be charted.
@@ -213,6 +217,18 @@ async def create_virtual_dataset(
url=None,
error=f"Failed to update dataset metadata (creation rolled back): {exc}",
)
except SupersetGenericDBErrorException as exc:
logger.warning("Virtual dataset SQL validation failed", exc_info=True)
await ctx.warning(f"Virtual dataset SQL failed validation: {exc}")
return CreateVirtualDatasetResponse(
id=None,
dataset_name=request.dataset_name,
sql=request.sql,
database_id=request.database_id,
columns=[],
url=None,
error=f"Dataset SQL could not be executed: {exc}",
)
except Exception as exc:
await ctx.error(
f"Unexpected error creating virtual dataset: {type(exc).__name__}: {exc}"
+3 -4
View File
@@ -653,10 +653,9 @@ def _build_composite_verifier(
if api_key_enabled:
if required_scopes := app.config.get("MCP_REQUIRED_SCOPES", []):
logger.warning(
"MCP_REQUIRED_SCOPES is configured but API key tokens bypass "
"scope enforcement. API key holders gain access regardless of "
"MCP_REQUIRED_SCOPES=%r. Enforce per-key authorization via FAB "
"roles/RBAC instead.",
"MCP_REQUIRED_SCOPES=%r is configured, but API key tokens use "
"the scopes stored on each key instead. Unscoped API keys "
"retain legacy RBAC-only behavior.",
required_scopes,
)
raw_prefixes: str | Sequence[str] = app.config.get(
@@ -30,7 +30,7 @@ from fastmcp import Context
from superset_core.mcp.decorators import tool, ToolAnnotations
from superset.extensions import event_logger
from superset.mcp_service.auth import MCPPermissionDeniedError
from superset.mcp_service.auth import _token_scope_allows, MCPPermissionDeniedError
from superset.mcp_service.common.schema_discovery import (
CHART_DEFAULT_COLUMNS,
CHART_SEARCH_COLUMNS,
@@ -235,9 +235,10 @@ async def get_schema(
from superset import security_manager
if current_app.config.get("MCP_RBAC_ENABLED", True) and not (
security_manager.can_access("can_read", class_permission)
):
rbac_allows = not current_app.config.get(
"MCP_RBAC_ENABLED", True
) or security_manager.can_access("can_read", class_permission)
if not (rbac_allows and _token_scope_allows("read", class_permission)):
user_str = getattr(getattr(g, "user", None), "username", None)
logger.warning(
"get_schema RBAC denied: user=%s type=%s view=%s",
+207 -3
View File
@@ -19,6 +19,7 @@
from __future__ import annotations
import ast
import builtins
import copy
import dataclasses
@@ -417,6 +418,52 @@ UUID_NATIVE_TYPE_RE: re.Pattern[str] = re.compile(
)
def parse_array_literal(value: Any) -> list[Any]:
"""
Parse a user-entered array literal (e.g. ``['a', 'b']`` or ``[1, 2]``) into a
list of elements, for the whole-array (column-level) array operators.
Accepts either an actual list/tuple, a bracketed literal string (parsed with
``ast.literal_eval``), or a plain scalar (wrapped into a single-element list).
Falls back to a single-element list when the string is not a valid literal.
"""
if isinstance(value, (list, tuple)):
return list(value)
if isinstance(value, str):
stripped = value.strip()
if stripped.startswith("[") and stripped.endswith("]"):
try:
parsed = ast.literal_eval(stripped)
except (ValueError, SyntaxError):
parsed = None
if isinstance(parsed, (list, tuple)):
return list(parsed)
return [value]
def coerce_array_values(
values: list[Any], element_type: Optional[utils.GenericDataType]
) -> list[Any]:
"""
Coerce array-element ``values`` to the array column's element type so the
emitted literal matches the column. Array columns map to a SQLAlchemy
``String`` type, so values arrive as strings and would otherwise build
string literals (e.g. ``array('5')``) that fail against a numeric array on
the server. Numeric elements are cast to numbers and boolean elements to
booleans; every other element type (string, temporal, enum, unknown) is left
untouched.
:param values: element values entered for an array filter
:param element_type: the array's element :class:`GenericDataType`, or None
:return: the coerced values
"""
if element_type == utils.GenericDataType.NUMERIC:
return [utils.cast_to_num(v) if isinstance(v, str) else v for v in values]
if element_type == utils.GenericDataType.BOOLEAN:
return [utils.cast_to_boolean(v) if isinstance(v, str) else v for v in values]
return values
def is_uuid_native_type(native_type: Optional[str]) -> bool:
"""
Return True if a native column type represents a UUID.
@@ -3652,6 +3699,7 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
column_name: str,
limit: int = 10000,
denormalize_column: bool = False,
array_elements: bool = False,
) -> list[Any]:
# denormalize column name before querying for values
# unless disabled in the dataset configuration
@@ -3666,13 +3714,25 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
tp = self.get_template_processor()
tbl, cte = self.get_from_clause(tp)
db_engine_spec = self.database.db_engine_spec
value_expr = target_col.get_sqla_col(template_processor=tp)
# For element-level operators (Contains any / Contains all) on a
# multi-value (array) column, suggest the distinct **elements** rather
# than distinct whole arrays by expanding the array first (e.g. ClickHouse
# arrayJoin). Only when the engine supports arrays and the column is
# actually an array column; otherwise fall back to whole-value suggestions.
if array_elements and db_engine_spec.supports_multivalue_columns:
col_spec = db_engine_spec.get_column_spec(native_type=target_col.type)
if col_spec and col_spec.generic_type == GenericDataType.MULTI_VALUE:
value_expr = db_engine_spec.array_explode(value_expr)
qry = (
sa.select(
# The alias (label) here is important because some dialects will
# automatically add a random alias to the projection because of the
# call to DISTINCT; others will uppercase the column names. This
# gives us a deterministic column name in the dataframe.
target_col.get_sqla_col(template_processor=tp).label("column_values")
value_expr.label("column_values")
)
.select_from(tbl)
.distinct()
@@ -4359,7 +4419,7 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
elif is_adhoc_column(flt_col):
try:
sqla_col, adhoc_generic_type = self.adhoc_column_to_sqla(
flt_col,
cast("AdhocColumn", flt_col),
force_type_check=True,
template_processor=template_processor,
)
@@ -4433,9 +4493,21 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
sqla_col = Grouping(sqla_col)
col_type = col_obj.type if col_obj else None
col_spec = db_engine_spec.get_column_spec(native_type=col_type)
is_multivalue_col = bool(
col_spec and col_spec.generic_type == GenericDataType.MULTI_VALUE
)
# Element type of an array column (e.g. Array(Int32) -> NUMERIC),
# used to coerce filter values before building array expressions.
array_element_type = (
db_engine_spec.get_array_element_type(col_type)
if is_multivalue_col
else None
)
is_list_target = op in (
utils.FilterOperator.IN,
utils.FilterOperator.NOT_IN,
utils.FilterOperator.CONTAINS_ANY,
utils.FilterOperator.CONTAINS_ALL,
)
col_advanced_data_type = col_obj.advanced_data_type if col_obj else ""
@@ -4490,7 +4562,56 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
sqla_col, op, bus_resp["values"]
)
)
elif is_list_target:
elif is_multivalue_col and op in {
utils.FilterOperator.EQUALS,
utils.FilterOperator.NOT_EQUALS,
utils.FilterOperator.IN,
utils.FilterOperator.NOT_IN,
}:
# Whole-array (column-level) comparison against array
# literal(s). The value is a pasted array literal like
# ``['a', 'b']`` (parsed into elements): ``col = ['a', 'b']``
# for = / !=; for IN / NOT IN each entered value is one such
# array literal (``col IN (['a'], ['b'])``).
if op in {
utils.FilterOperator.EQUALS,
utils.FilterOperator.NOT_EQUALS,
}:
literal = db_engine_spec.array_literal(
coerce_array_values(
parse_array_literal(val), array_element_type
)
)
cond = (
sqla_col != literal
if op == utils.FilterOperator.NOT_EQUALS
else sqla_col == literal
)
else:
candidates: list[Any] = (
list(val) if isinstance(val, (list, tuple)) else [val]
)
cond = sqla_col.in_(
[
db_engine_spec.array_literal(
coerce_array_values(
parse_array_literal(candidate),
array_element_type,
)
)
for candidate in candidates
]
)
if op == utils.FilterOperator.NOT_IN:
cond = ~cond
target_clause_list.append(cond)
elif op in {
utils.FilterOperator.IN,
utils.FilterOperator.NOT_IN,
}:
# CONTAINS_ANY/CONTAINS_ALL also produce a list ``eq`` (they
# are in ``is_list_target``), but are element-level array ops
# handled by their own branch below — not IN.
assert isinstance(eq, (tuple, list))
if len(eq) == 0:
raise QueryObjectValidationError(
@@ -4529,6 +4650,57 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
target_clause_list.append(
db_engine_spec.handle_null_filter(sqla_col, op)
)
elif op in {
utils.FilterOperator.IS_EMPTY,
utils.FilterOperator.IS_NOT_EMPTY,
}:
# Element-level array operators: length(col) == 0 / > 0.
if target_generic_type != GenericDataType.MULTI_VALUE:
raise QueryObjectValidationError(
_(
"The %(op)s operator is only supported for "
"multi-value (array) columns.",
op=op,
)
)
length_expr = db_engine_spec.array_length(sqla_col)
if op == utils.FilterOperator.IS_EMPTY:
target_clause_list.append(length_expr == 0)
else:
target_clause_list.append(length_expr > 0)
elif op in {
utils.FilterOperator.LENGTH_EQUALS,
utils.FilterOperator.LENGTH_GREATER_THAN,
utils.FilterOperator.LENGTH_LESS_THAN,
utils.FilterOperator.LENGTH_GREATER_THAN_OR_EQUALS,
utils.FilterOperator.LENGTH_LESS_THAN_OR_EQUALS,
}:
# Length filter: compare the array's element count to a
# number, e.g. length(col) > 2.
if target_generic_type != GenericDataType.MULTI_VALUE:
raise QueryObjectValidationError(
_(
"The %(op)s operator is only supported for "
"multi-value (array) columns.",
op=op,
)
)
number = utils.cast_to_num(eq) # type: ignore[arg-type]
if number is None:
raise QueryObjectValidationError(
_("The Length filter requires a numeric value.")
)
length_expr = db_engine_spec.array_length(sqla_col)
length_comparisons = {
utils.FilterOperator.LENGTH_EQUALS: length_expr == number,
utils.FilterOperator.LENGTH_GREATER_THAN: length_expr > number,
utils.FilterOperator.LENGTH_LESS_THAN: length_expr < number,
utils.FilterOperator.LENGTH_GREATER_THAN_OR_EQUALS: length_expr
>= number,
utils.FilterOperator.LENGTH_LESS_THAN_OR_EQUALS: length_expr
<= number,
}
target_clause_list.append(length_comparisons[op])
elif op == utils.FilterOperator.IS_TRUE:
target_clause_list.append(
db_engine_spec.handle_boolean_filter(sqla_col, op, True)
@@ -4586,6 +4758,38 @@ class ExploreMixin: # pylint: disable=too-many-public-methods
target_clause_list.append(sqla_col.not_like(eq))
else:
target_clause_list.append(sqla_col.not_ilike(eq))
elif op in {
utils.FilterOperator.CONTAINS_ANY,
utils.FilterOperator.CONTAINS_ALL,
}:
# Element-level array membership. Enforce the target is
# actually a multi-value (array) column (only classified
# MULTI_VALUE on an array-capable engine), guarding against
# payloads that bypass the UI gating.
if target_generic_type != GenericDataType.MULTI_VALUE:
raise QueryObjectValidationError(
_(
"The %(op)s operator is only supported for "
"multi-value (array) columns.",
op=op,
)
)
array_values: list[Any] = coerce_array_values(
list(eq) if isinstance(eq, (list, tuple)) else [eq],
array_element_type,
)
if op == utils.FilterOperator.CONTAINS_ANY:
target_clause_list.append(
db_engine_spec.array_contains_any(
sqla_col, array_values
)
)
else:
target_clause_list.append(
db_engine_spec.array_contains_all(
sqla_col, array_values
)
)
elif (
op == utils.FilterOperator.TEMPORAL_RANGE
and isinstance(eq, str)
+77
View File
@@ -0,0 +1,77 @@
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
"""Canonical resource and action mappings for scoped API keys."""
# Map FAB method permissions used by MCP tools to the coarser actions supported
# by API-key scopes. Keep this explicit so an unknown permission fails closed.
METHOD_PERMISSION_SCOPE_ACTION: dict[str, str] = {
"read": "read",
"get": "read",
"write": "write",
"update": "write",
"delete": "write",
"execute_sql_query": "write",
}
# Map MCP/FAB class permission names to stable public resource slugs. These
# cannot be derived by lowercasing because several names contain spaces or use
# public spellings that differ from their internal class names.
RESOURCE_SCOPE_NAME: dict[str, str] = {
"Annotation": "annotation",
"Chart": "chart",
"Dashboard": "dashboard",
"Database": "database",
"Dataset": "dataset",
"Explore": "explore",
"Query": "query",
"ReportSchedule": "report",
"Role": "role",
"Row Level Security": "rls",
"SavedQuery": "savedquery",
"SQLLab": "sqllab",
"Tag": "tag",
"Task": "task",
"Theme": "theme",
"User": "user",
}
RESOURCE_SCOPE_CLASS: dict[str, str] = {
resource: class_name for class_name, resource in RESOURCE_SCOPE_NAME.items()
}
RESOURCE_SCOPE_ACTIONS: frozenset[str] = frozenset(
METHOD_PERMISSION_SCOPE_ACTION.values()
)
SCOPE_ACTION_METHOD_PERMISSIONS: dict[str, tuple[str, ...]] = {
action: tuple(
method
for method, mapped_action in METHOD_PERMISSION_SCOPE_ACTION.items()
if mapped_action == action
)
for action in RESOURCE_SCOPE_ACTIONS
}
def get_resource_scope(
class_permission_name: str, method_permission_name: str
) -> str | None:
"""Return the resource scope required by a FAB class/method permission."""
resource = RESOURCE_SCOPE_NAME.get(class_permission_name)
action = METHOD_PERMISSION_SCOPE_ACTION.get(method_permission_name)
if resource is None or action is None:
return None
return f"superset:{resource}:{action}"
+237 -27
View File
@@ -17,6 +17,7 @@
# pylint: disable=too-many-lines
"""A set of constants and methods to manage permissions and security"""
import datetime
import logging
import re
import time
@@ -36,7 +37,7 @@ from urllib.parse import quote
from flask import current_app, Flask, g, has_app_context, Request, Response
from flask_appbuilder import Model
from flask_appbuilder.api import expose, protect, safe
from flask_appbuilder.api import expose, permission_name, protect, safe
from flask_appbuilder.models.filters import BaseFilter
from flask_appbuilder.security.manager import AUTH_REMOTE_USER
from flask_appbuilder.security.sqla.apis import GroupApi, RoleApi, UserApi
@@ -394,8 +395,11 @@ class SupersetUserApi(UserApi):
"""
Overriding the UserApi to sync Subject rows, filter excluded users,
handle deletion constraints, and add audit logging.
UserApi has custom post/put that bypass hooks, so we override them
and sync after the parent method succeeds.
The Subject sync happens in ``pre_add``/``pre_update``, which FAB calls
*before* the commit that ``self.datamodel.add``/``edit`` issues -- so the
sync rides that same commit rather than needing one of its own after the
fact.
"""
base_filters = [["username", ExcludeUsersFilter, lambda: []]]
@@ -415,6 +419,45 @@ class SupersetUserApi(UserApi):
"changed_on",
]
def pre_add(self, item: Model) -> None:
"""Hash the password (FAB's own ``pre_add``), then sync the user's
``Subject`` row before FAB's own commit.
``UserApi.post`` calls ``pre_add`` *before* ``self.datamodel.add``,
which is what actually issues the commit -- so flushing the new user
here (to obtain its id) and syncing its ``Subject`` row alongside it
means both writes ride the same transaction and commit together,
instead of the subject sync needing a second, separate commit after
the fact.
"""
super().pre_add(item)
from superset.daos.user import UserDAO
self.datamodel.session.add(item)
self.datamodel.session.flush()
UserDAO._sync_subject(item)
def pre_update(self, item: Model, data: dict[str, Any]) -> None:
"""Same reasoning as ``pre_add``: ``UserApi.put`` calls ``pre_update``
before ``self.datamodel.edit`` commits, so the subject sync lands in
that same transaction.
"""
super().pre_update(item, data)
from superset.daos.user import UserDAO
UserDAO._sync_subject(item)
if data.get("password"):
# An admin-initiated password change via this endpoint must
# invalidate the target account's other outstanding sessions,
# the same as the self-service ``/me/`` path and the two
# password-reset views.
from superset.security.session_invalidation import (
invalidate_sessions_for_user,
)
invalidate_sessions_for_user(item.id)
@expose("/", methods=["POST"])
@protect()
@safe
@@ -430,17 +473,7 @@ class SupersetUserApi(UserApi):
500:
description: Server error
"""
response = super().post()
if response.status_code == 201:
from superset.daos.user import UserDAO
user_id = response.json.get("id")
if user_id:
user = self.datamodel.session.get(self.datamodel.obj, user_id)
if user:
UserDAO._sync_subject(user)
self.datamodel.session.commit() # pylint: disable=consider-using-transaction
return response
return super().post()
@expose("/<pk>", methods=["PUT"])
@protect()
@@ -464,15 +497,42 @@ class SupersetUserApi(UserApi):
500:
description: Server error
"""
response = super().put(pk)
if response.status_code == 200:
from superset.daos.user import UserDAO
return super().put(pk)
user = self.datamodel.get(pk, self._base_filters)
if user:
UserDAO._sync_subject(user)
self.datamodel.session.commit() # pylint: disable=consider-using-transaction
return response
@expose("/<int:pk>/sessions", methods=["DELETE"])
@protect()
@permission_name("put")
@safe
def terminate_sessions(self, pk: int) -> Response:
"""Terminate a user's outstanding sessions without disabling their account.
---
delete:
parameters:
- in: path
name: pk
schema:
type: integer
responses:
200:
description: Sessions terminated
404:
$ref: '#/components/responses/404'
500:
$ref: '#/components/responses/500'
"""
from superset.security.session_invalidation import invalidate_sessions_for_user
user = self.datamodel.get(pk, self._base_filters)
if not user:
return self.response_404()
invalidate_sessions_for_user(user.id)
self.datamodel.session.commit() # pylint: disable=consider-using-transaction
_log_audit_event(
"UserSessionsTerminated",
{"target_username": user.username, "target_user_id": user.id},
)
return self.response(200, message="User sessions terminated.")
def pre_delete(self, item: Model) -> None:
from superset.daos.user import UserDAO
@@ -754,15 +814,24 @@ def _native_filter_query_modified(
query: Any, allowed_columns: set[str], allowed_metrics: set[str]
) -> bool:
"""Whether a single query in a native-filter request reads beyond its targets."""
# Columns and group-by may only reference target column(s); adhoc (free-form
# SQL) columns cannot be validated, so reject them.
for key in ("columns", "groupby"):
# Columns, group-by, and series columns may only reference target column(s);
# adhoc (free-form SQL) columns cannot be validated, so reject them.
for key in ("columns", "groupby", "series_columns"):
for col in getattr(query, key, None) or []:
if not isinstance(col, str) or col not in allowed_columns:
return True
for metric in getattr(query, "metrics", None) or []:
if not _native_filter_term_allowed(metric, allowed_columns, allowed_metrics):
return True
# A series-limit metric ranks the top-N groups in the inner query, so it is
# a value-returning term and is validated like a metric. ``QueryObject``
# renames the deprecated ``timeseries_limit_metric`` payload key onto this
# attribute, so both spellings are covered.
series_limit_metric = getattr(query, "series_limit_metric", None)
if series_limit_metric and not _native_filter_term_allowed(
series_limit_metric, allowed_columns, allowed_metrics
):
return True
# order-by entries are ``(expression, asc)`` pairs.
for order in getattr(query, "orderby", None) or []:
expr = order[0] if isinstance(order, (list, tuple)) and order else order
@@ -784,8 +853,9 @@ def _native_filter_request_modified(query_context: "QueryContext") -> bool:
A native filter may only read the column(s) it targets on the dashboard it
belongs to. The request is treated as modified (and therefore rejected for
guest users) when it cannot be tied to a native filter on the requesting
dashboard, or when any value-returning term (column, group-by, metric, or
order-by) references something other than a target column, a simple
dashboard, or when any value-returning term (column, group-by, series
column, metric, series-limit metric, or order-by) references something
other than a target column, a simple
aggregate over a target column, or the filter's configured sort metric.
Free-form SQL terms and saved metrics other than the configured sort metric
are rejected. Row-restricting clauses (``filter``/``extras``) are not
@@ -1555,9 +1625,23 @@ class SupersetSecurityManager( # pylint: disable=too-many-public-methods
bypassed. We distinguish the two by comparing the acting user
(``g.user``) against the target ``userid``: they match for a
self-service reset and differ for an admin reset.
Also stamps the session-invalidation epoch for the target user, so
any session for the account that predates this reset stops working --
regardless of which of the two paths triggered it.
"""
super().reset_password(userid, password)
# pylint: disable=import-outside-toplevel
from superset import db
from superset.security.session_invalidation import invalidate_sessions_for_user
invalidate_sessions_for_user(int(userid))
# ``super().reset_password`` (FAB's ``update_user``) already committed
# its own change in a separate transaction, so the epoch stamp above
# needs its own commit too, rather than riding an existing one.
db.session.commit() # pylint: disable=consider-using-transaction
acting_user = getattr(g, "user", None)
acting_user_id = getattr(acting_user, "id", None)
# ``userid`` arrives as a string (the ``pk`` request arg) on the admin
@@ -4297,6 +4381,15 @@ class SupersetSecurityManager( # pylint: disable=too-many-public-methods
child_slice_id=slice_id,
parent_slice=parent_slc,
)
# Bind the request to the child
# chart's own datasource, mirroring
# the direct-chart leg above.
and (
child_slc := self.session.query(Slice)
.filter(Slice.id == slice_id)
.one_or_none()
)
and child_slc.datasource == datasource
)
)
)
@@ -4926,6 +5019,123 @@ class SupersetSecurityManager( # pylint: disable=too-many-public-methods
raw_token, secret, algorithms=[algo], audience=audience
)
def get_api_key_scopes(self, api_key_string: str) -> Optional[str]:
"""Return the ``scopes`` value for a validated API key.
FAB's ``validate_api_key`` resolves the matching ``ApiKey`` row
internally (by lookup hash) but only returns the associated
``User`` the row's ``scopes`` column is otherwise unreachable by
callers. This repeats the same cheap, indexed lookup so MCP's
``CompositeTokenVerifier`` can propagate per-key scopes instead of
silently falling back to verifier-global scopes. Call only after
``validate_api_key`` has already succeeded for this token this
method does not itself verify the key hash or active status.
"""
lookup = self._compute_lookup_hash(api_key_string) # type: ignore[attr-defined]
api_key = (
self.session.query(self.api_key_model) # type: ignore[attr-defined]
.filter(self.api_key_model.lookup_hash == lookup)
.one_or_none()
)
return api_key.scopes if api_key else None
def _validate_requested_api_key_scopes(
self, user: Any, scopes: Optional[str]
) -> None:
"""Raise if ``scopes`` would grant a user more than their own RBAC.
Enforces the "intersection, never broader" rule confirmed for this
feature: a user must never be able to mint a token scoped beyond
what their own role already permits, even if they hand-author the
scopes string themselves at issuance time.
Per-resource scopes (``superset:<resource>:<action>``) are checked
against the user's actual ``can_<method>`` RBAC grant for that
resource. Flat scopes (``superset:read``/``superset:write``, the
pre-per-resource form) can only be self-issued by Admins a flat
scope grants a method across every resource, and there's no single
RBAC check that soundly proves a non-Admin has that for "every
resource," so it's rejected for anyone else rather than guessed at.
Unrecognized scope strings are rejected outright (fail closed).
NOTE: this only prevents the request from being honored; it does
not (yet) produce a clean 400 response, since FAB's ``ApiKeyApi``
has no validation hook this can plug into without replacing the API
registration entirely. Raising here surfaces as a 500 via FAB's
``@safe`` decorator until that's addressed — tracked as a known
follow-up, not silently accepted.
"""
if not scopes:
return
# pylint: disable-next=import-outside-toplevel
from superset.security.api_key_scopes import (
RESOURCE_SCOPE_ACTIONS,
RESOURCE_SCOPE_CLASS,
SCOPE_ACTION_METHOD_PERMISSIONS,
)
admin_role_name = get_conf()["AUTH_ROLE_ADMIN"]
is_admin = any(
role.name == admin_role_name for role in getattr(user, "roles", [])
)
for raw_scope in scopes.split(","):
scope = raw_scope.strip()
if not scope:
continue
parts = scope.split(":")
if len(parts) == 3 and parts[0] == "superset":
_, resource_slug, action = parts
class_permission_name = RESOURCE_SCOPE_CLASS.get(resource_slug)
if class_permission_name is None:
raise ValueError(
f"Requested scope '{scope}' names an unrecognized "
f"resource '{resource_slug}'"
)
if action not in RESOURCE_SCOPE_ACTIONS:
raise ValueError(
f"Requested scope '{scope}' names an unrecognized "
f"action '{action}'"
)
if any(
self._has_view_access(user, f"can_{method}", class_permission_name)
for method in SCOPE_ACTION_METHOD_PERMISSIONS[action]
):
continue
raise ValueError(
f"Requested scope '{scope}' exceeds the issuing user's "
"own permissions"
)
if (
len(parts) == 2
and parts[0] == "superset"
and parts[1] in RESOURCE_SCOPE_ACTIONS
and is_admin
):
continue
raise ValueError(
f"Requested scope '{scope}' is not a recognized "
"superset:<resource>:<action> scope, or requires Admin to "
"self-issue as a flat scope"
)
def create_api_key(
self,
user: Any,
name: str,
scopes: Optional[str] = None,
expires_on: Optional[datetime.datetime] = None,
) -> Optional[dict[str, Any]]:
"""Create a new API key, enforcing the scope-intersection rule.
Thin wrapper around FAB's ``SecurityManager.create_api_key`` — see
``_validate_requested_api_key_scopes`` for the actual check. FAB's
base implementation is otherwise unchanged.
"""
self._validate_requested_api_key_scopes(user, scopes)
return super().create_api_key( # type: ignore[misc]
user=user, name=name, scopes=scopes, expires_on=expires_on
)
@staticmethod
def is_guest_user(user: Optional[Any] = None) -> bool:
# pylint: disable=import-outside-toplevel

Some files were not shown because too many files have changed in this diff Show More