Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion superset/charts/schemas.py
Original file line number Diff line number Diff line change
Expand Up @@ -269,7 +269,9 @@ class ChartPutSchema(Schema):
)
owners = fields.List(fields.Integer(metadata={"description": owners_description}))
params = fields.String(
metadata={"description": params_description}, allow_none=True
metadata={"description": params_description},
allow_none=True,
validate=utils.validate_json,
)
query_context = fields.String(
metadata={"description": query_context_description}, allow_none=True
Expand Down
44 changes: 37 additions & 7 deletions superset/connectors/sqla/models.py
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,7 @@
SupersetErrorsException,
SupersetGenericDBErrorException,
SupersetSecurityException,
SupersetSyntaxErrorException,
)
from superset.jinja_context import (
BaseTemplateProcessor,
Expand Down Expand Up @@ -686,11 +687,12 @@ def get_sqla_row_level_filters(
grouped_filters = [or_(*clauses) for clauses in filter_groups.values()]
all_filters.extend(grouped_filters)
return all_filters
except TemplateError as ex:
except (TemplateError, SupersetSyntaxErrorException) as ex:
msg = getattr(ex, "message", str(ex))
raise QueryObjectValidationError(
_(
"Error in jinja expression in RLS filters: %(msg)s",
msg=ex.message,
msg=msg,
)
) from ex

Expand Down Expand Up @@ -893,7 +895,16 @@ def get_sqla_col(
type_ = column_spec.sqla_type if column_spec else None
if expression := self.expression:
if template_processor:
expression = template_processor.process_template(expression)
try:
expression = template_processor.process_template(expression)
except SupersetSyntaxErrorException as ex:
msg = str(ex)
raise QueryObjectValidationError(
_(
"Error in jinja expression in column expression: %(msg)s",
msg=msg,
)
) from ex
col = literal_column(expression, type_=type_)
else:
col = column(self.column_name, type_=type_)
Expand Down Expand Up @@ -931,7 +942,16 @@ def get_timestamp_expression(
return self.database.make_sqla_column_compatible(sqla_col, label)
if expression := self.expression:
if template_processor:
expression = template_processor.process_template(expression)
try:
expression = template_processor.process_template(expression)
except SupersetSyntaxErrorException as ex:
msg = str(ex)
raise QueryObjectValidationError(
_(
"Error in jinja expression in datetime column: %(msg)s",
msg=msg,
)
) from ex
col = literal_column(expression, type_=type_)
else:
col = column(self.column_name, type_=type_)
Expand Down Expand Up @@ -1012,7 +1032,16 @@ def get_sqla_col(
label = label or self.metric_name
expression = self.expression
if template_processor:
expression = template_processor.process_template(expression)
try:
expression = template_processor.process_template(expression)
except SupersetSyntaxErrorException as ex:
msg = str(ex)
raise QueryObjectValidationError(
_(
"Error in jinja expression in metric expression: %(msg)s",
msg=msg,
)
) from ex

sqla_col: ColumnClause = literal_column(expression)
return self.table.database.make_sqla_column_compatible(sqla_col, label)
Expand Down Expand Up @@ -1356,11 +1385,12 @@ def get_fetch_values_predicate(
)
try:
return self.text(fetch_values_predicate)
except TemplateError as ex:
except (TemplateError, SupersetSyntaxErrorException) as ex:
msg = getattr(ex, "message", str(ex))
raise QueryObjectValidationError(
_(
"Error in jinja expression in fetch values predicate: %(msg)s",
msg=ex.message,
msg=msg,
)
) from ex

Expand Down
12 changes: 9 additions & 3 deletions superset/connectors/sqla/utils.py
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@
SupersetGenericDBErrorException,
SupersetParseError,
SupersetSecurityException,
SupersetSyntaxErrorException,
)
from superset.models.core import Database
from superset.result_set import SupersetResultSet
Expand Down Expand Up @@ -103,9 +104,14 @@ def get_virtual_table_metadata(dataset: SqlaTable) -> list[ResultSetColumnType]:
)

db_engine_spec = dataset.database.db_engine_spec
sql = dataset.get_template_processor().process_template(
dataset.sql, **dataset.template_params_dict
)
try:
sql = dataset.get_template_processor().process_template(
dataset.sql, **dataset.template_params_dict
)
except SupersetSyntaxErrorException as ex:
raise SupersetGenericDBErrorException(
message=_("Template processing error: %(error)s", error=str(ex)),
) from ex
try:
parsed_script = SQLScript(sql, engine=db_engine_spec.engine)
except SupersetParseError as ex:
Expand Down
14 changes: 9 additions & 5 deletions superset/datasets/api.py
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,10 @@
GetOrCreateDatasetSchema,
openapi_spec_methods_override,
)
from superset.exceptions import SupersetTemplateException
from superset.exceptions import (
SupersetSyntaxErrorException,
SupersetTemplateException,
)
from superset.jinja_context import BaseTemplateProcessor, get_template_processor
from superset.utils import json
from superset.utils.core import parse_boolean_string
Expand Down Expand Up @@ -1175,7 +1178,7 @@ def get(self, id_or_uuid: str, **kwargs: Any) -> Response:
response["result"], processor
)
except SupersetTemplateException as ex:
return self.response_400(message=str(ex))
return self.response(ex.status, message=str(ex))

return self.response(200, **response)

Expand Down Expand Up @@ -1315,9 +1318,10 @@ def render_item_list(item_list: list[dict[str, Any]]) -> list[dict[str, Any]]:

try:
data[new_key] = func(data[key])
except TemplateSyntaxError as ex:
raise SupersetTemplateException(
except (TemplateSyntaxError, SupersetSyntaxErrorException) as ex:
template_exception = SupersetTemplateException(
f"Unable to render expression from dataset {item_type}.",
) from ex
)
raise template_exception from ex

return data
2 changes: 1 addition & 1 deletion superset/exceptions.py
Original file line number Diff line number Diff line change
Expand Up @@ -188,7 +188,7 @@ class NullValueException(SupersetException):


class SupersetTemplateException(SupersetException):
pass
status = 422


class SpatialException(SupersetException):
Expand Down
77 changes: 73 additions & 4 deletions superset/jinja_context.py
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@

from __future__ import annotations

import logging
import re
from dataclasses import dataclass
from datetime import datetime
Expand All @@ -27,7 +28,8 @@
import dateutil
from flask import current_app, g, has_request_context, request
from flask_babel import gettext as _
from jinja2 import DebugUndefined, Environment
from jinja2 import DebugUndefined, Environment, TemplateSyntaxError
from jinja2.exceptions import SecurityError, UndefinedError
from jinja2.sandbox import SandboxedEnvironment
from sqlalchemy.engine.interfaces import Dialect
from sqlalchemy.sql.expression import bindparam
Expand All @@ -37,7 +39,11 @@
from superset.commands.dataset.exceptions import DatasetNotFoundError
from superset.common.utils.time_range_utils import get_since_until_from_time_range
from superset.constants import LRU_CACHE_MAX_SIZE, NO_TIME_RANGE
from superset.exceptions import SupersetTemplateException
from superset.errors import ErrorLevel, SupersetError, SupersetErrorType
from superset.exceptions import (
SupersetSyntaxErrorException,
SupersetTemplateException,
)
from superset.extensions import feature_flag_manager
from superset.sql.parse import Table
from superset.utils import json
Expand All @@ -56,6 +62,8 @@
from superset.models.core import Database
from superset.models.sql_lab import Query

logger = logging.getLogger(__name__)

NONE_TYPE = type(None).__name__
ALLOWED_TYPES = (
NONE_TYPE,
Expand Down Expand Up @@ -688,10 +696,71 @@ def process_template(self, sql: str, **kwargs: Any) -> str:
>>> process_template(sql)
"SELECT '2017-01-01T00:00:00'"
"""
template = self.env.from_string(sql)
kwargs.update(self._context)
try:
template = self.env.from_string(sql)
except (
TemplateSyntaxError,
SecurityError,
UndefinedError,
UnicodeError,
UnicodeDecodeError,
UnicodeEncodeError,
) as ex:
error_msg = str(ex)
exception_type = type(ex).__name__

message = f"Jinja2 template error ({exception_type}): {error_msg}"

line_number = getattr(ex, "lineno", None)

logger.warning(
"Jinja2 template client error",
extra={
"error_message": error_msg,
"template_snippet": sql[:200] if sql else None,
"template_length": len(sql) if sql else 0,
"line_number": line_number,
"error_type": "CLIENT_TEMPLATE_ERROR",
"exception_type": exception_type,
},
exc_info=False,
)

error = SupersetError(
message=message,
error_type=SupersetErrorType.GENERIC_COMMAND_ERROR,
level=ErrorLevel.ERROR,
extra={
"template": sql[:500],
"line": line_number,
"exception_type": exception_type,
},
)

raise SupersetSyntaxErrorException([error]) from ex
except Exception as ex:
error_msg = str(ex)
exception_type = type(ex).__name__

message = f"Internal Jinja2 template error ({exception_type}): {error_msg}"

logger.error(
"Jinja2 template server error",
extra={
"error_message": error_msg,
"template_snippet": sql[:200] if sql else None,
"template_length": len(sql) if sql else 0,
"error_type": "SERVER_TEMPLATE_ERROR",
"exception_type": exception_type,
},
exc_info=True,
)

raise SupersetTemplateException(message) from ex

kwargs.update(self._context)
context = validate_template_context(self.engine, kwargs)

try:
return template.render(context)
except RecursionError as ex:
Expand Down
13 changes: 10 additions & 3 deletions superset/models/helpers.py
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,7 @@
QueryClauseValidationException,
QueryObjectValidationError,
SupersetSecurityException,
SupersetSyntaxErrorException,
)
from superset.extensions import feature_flag_manager
from superset.jinja_context import BaseTemplateProcessor
Expand Down Expand Up @@ -1082,11 +1083,17 @@ def get_rendered_sql(
if template_processor:
try:
sql = template_processor.process_template(sql)
except TemplateError as ex:
except (TemplateError, SupersetSyntaxErrorException) as ex:
# Extract error message from different exception types
if isinstance(ex, TemplateError):
error_msg = ex.message
else: # SupersetSyntaxErrorException
error_msg = str(ex.errors[0].message if ex.errors else ex)

raise QueryObjectValidationError(
_(
"Error while rendering virtual dataset query: %(msg)s",
msg=ex.message,
msg=error_msg,
)
) from ex

Expand Down Expand Up @@ -1505,7 +1512,7 @@ def validate_expression(
)
except Exception as ex:
# Convert any exception to validation error format
error_msg = str(ex.orig) if hasattr(ex, "orig") else str(ex)
error_msg = str(getattr(ex, "orig", ex))
return ValidationResultDict(
valid=False,
errors=[
Expand Down
Loading
Loading