New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Implement view access permission for Dashboard and Query resources. #2011
Conversation
678b5e0
to
b31b5f4
Compare
Thanks! I'll review this once v3 is released (beta should be this week 🤞). |
@arikfr would you like to merge this into master? Since these changes effect the core of the application, with each new feature, the risk of loosing the track of the code increases. |
Thank you for the follow up, @meinac. I didn't have the chance to properly review this after the There are security implications here that need to be reviewed properly, but also I feel that there are few product aspects that we need to think about in a more "holistic" way to make sure we don't apply a patch that will be hard to replace later on. Now that How's that sound? |
Anyone with write permissions, could generate the merge and inclusion of the changes into the main branch of source code ? please |
b31b5f4
to
d75265f
Compare
This feature will be available only if `FEATURE_SHOW_PERMISSIONS_CONTROL` and `FEATURE_ENABLE_VIEW_PERMISSION` flags are set as +True+. If user has view access to a dashboard objct, all the queries related to this dashboard will be accessible by the user but the otherway around is not possible.
3ec3259
to
dbcb2f7
Compare
Hi there! It's 2023 and there is still no way to give access to a specific dashboard to a specific group or user :// |
@arikfr Do you have any thoughts on when this might be implemented? Would love to utilize Redash more holistically within our org but would require user or group level permissions for dashboards. Thanks for all the hard work!! |
This feature will be available only if
FEATURE_SHOW_PERMISSIONS_CONTROL
and
FEATURE_ENABLE_VIEW_PERMISSION
flags are set as +True+.If user has view access to a dashboard objct, all the queries related to
this dashboard will be accessible by the user but the otherway around is
not possible.