mirror of
https://github.com/apache/superset.git
synced 2026-04-08 19:05:46 +00:00
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: Kamil Gabryjelski <kamil.gabryjelski@gmail.com>
63 lines
1.8 KiB
Python
63 lines
1.8 KiB
Python
# Licensed to the Apache Software Foundation (ASF) under one
|
|
# or more contributor license agreements. See the NOTICE file
|
|
# distributed with this work for additional information
|
|
# regarding copyright ownership. The ASF licenses this file
|
|
# to you under the Apache License, Version 2.0 (the
|
|
# "License"); you may not use this file except in compliance
|
|
# with the License. You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing,
|
|
# software distributed under the License is distributed on an
|
|
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
|
# KIND, either express or implied. See the License for the
|
|
# specific language governing permissions and limitations
|
|
# under the License.
|
|
from typing import Any
|
|
|
|
import pytest
|
|
|
|
from superset.extensions import csrf
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"app",
|
|
[{"WTF_CSRF_ENABLED": True}],
|
|
indirect=True,
|
|
)
|
|
def test_csrf_exempt_blueprints(app_context: None) -> None:
|
|
"""
|
|
Test that only FAB security API blueprints (which use token-based auth)
|
|
are exempt from CSRF protection.
|
|
"""
|
|
assert {blueprint.name for blueprint in csrf._exempt_blueprints} == {
|
|
"GroupApi",
|
|
"MenuApi",
|
|
"SecurityApi",
|
|
"OpenApi",
|
|
"PermissionViewMenuApi",
|
|
"SupersetRoleApi",
|
|
"SupersetUserApi",
|
|
"PermissionApi",
|
|
"ViewMenuApi",
|
|
}
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"app",
|
|
[
|
|
{
|
|
"WTF_CSRF_ENABLED": True,
|
|
"FAB_API_KEY_ENABLED": True,
|
|
}
|
|
],
|
|
indirect=True,
|
|
)
|
|
def test_csrf_exempt_blueprints_with_api_key(app: Any, app_context: None) -> None:
|
|
"""
|
|
Test that ApiKeyApi blueprint is CSRF-exempt when FAB_API_KEY_ENABLED
|
|
config is enabled.
|
|
"""
|
|
assert "ApiKeyApi" in {blueprint.name for blueprint in csrf._exempt_blueprints}
|