You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@superset.apache.org by "ivan-price-acted (via GitHub)" <gi...@apache.org> on 2023/04/17 07:11:59 UTC

[GitHub] [superset] ivan-price-acted commented on issue #22640: Dashboard RBAC access doesn't conform to documentation (and access permission exposes a possible security risk)

ivan-price-acted commented on issue #22640:
URL: https://github.com/apache/superset/issues/22640#issuecomment-1510822601

   Hi there, 
   
   100% agree with @sfirke , i'm wondering what the use-case is for allowing global access to datasets (through dashboards) that would otherwise not be visible, just because a dashboard is in draft ?
   
   It's certain that our users will occasionally forget to publish dashboards, which leaves us wide open to leaking data, especially because dashboard URLs are so easy to guess !
   
   I feel like I must be missing something somewhere because this seems to be a serious potential security hole for any org using superset for sensitive data, between disparate teams ?
   
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@superset.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@superset.apache.org
For additional commands, e-mail: notifications-help@superset.apache.org