home / github

Menu
  • Search all tables
  • GraphQL API

issue_comments

Table actions
  • GraphQL API for issue_comments

5 rows where issue = 1886350562 sorted by updated_at descending

✖
✖

✎ View and edit SQL

This data as json, CSV (advanced)

Suggested facets: created_at (date), updated_at (date)

user 1

  • simonw 5

issue 1

  • Don't show foreign key links to tables the user cannot access · 5 ✖

author_association 1

  • OWNER 5
id html_url issue_url node_id user created_at updated_at ▲ author_association body reactions issue performed_via_github_app
1710879239 https://github.com/simonw/datasette/issues/2178#issuecomment-1710879239 https://api.github.com/repos/simonw/datasette/issues/2178 IC_kwDOBm6k_c5l-fIH simonw 9599 2023-09-07T23:20:32Z 2023-09-07T23:20:32Z OWNER

To test that locally, use this YAML instead: yaml databases: content: allow: id: root tables: releases: allow: true And: ```yaml allow: id: root databases: content: tables: releases: allow: true

{
    "total_count": 0,
    "+1": 0,
    "-1": 0,
    "laugh": 0,
    "hooray": 0,
    "confused": 0,
    "heart": 0,
    "rocket": 0,
    "eyes": 0
}
Don't show foreign key links to tables the user cannot access 1886350562  
1710878391 https://github.com/simonw/datasette/issues/2178#issuecomment-1710878391 https://api.github.com/repos/simonw/datasette/issues/2178 IC_kwDOBm6k_c5l-e63 simonw 9599 2023-09-07T23:19:05Z 2023-09-07T23:19:05Z OWNER

This fix didn't work on Datasette Cloud. I used /-/permissions to debug it and saw this:

Only checking view-table is not enough: for my instance on Datasette Cloud the view permission check that should have failed was for the database or instance.

{
    "total_count": 0,
    "+1": 0,
    "-1": 0,
    "laugh": 0,
    "hooray": 0,
    "confused": 0,
    "heart": 0,
    "rocket": 0,
    "eyes": 0
}
Don't show foreign key links to tables the user cannot access 1886350562  
1710871095 https://github.com/simonw/datasette/issues/2178#issuecomment-1710871095 https://api.github.com/repos/simonw/datasette/issues/2178 IC_kwDOBm6k_c5l-dI3 simonw 9599 2023-09-07T23:07:16Z 2023-09-07T23:07:16Z OWNER

I ran this:

datasette content.db -p 8043 -m fk-auth.yml --root

Against this YAML: yaml databases: content: tables: users: allow: id: root And it worked as it should - here's a screenshot of an anonymous user and a root user viewing the same page:

{
    "total_count": 0,
    "+1": 0,
    "-1": 0,
    "laugh": 0,
    "hooray": 0,
    "confused": 0,
    "heart": 0,
    "rocket": 0,
    "eyes": 0
}
Don't show foreign key links to tables the user cannot access 1886350562  
1710567329 https://github.com/simonw/datasette/issues/2178#issuecomment-1710567329 https://api.github.com/repos/simonw/datasette/issues/2178 IC_kwDOBm6k_c5l9S-h simonw 9599 2023-09-07T17:59:59Z 2023-09-07T17:59:59Z OWNER

Should I put the permission check in that undocumented datasette.expand_foreign_keys() method? I think so - it should accept request.actor as one of its arguments.

{
    "total_count": 0,
    "+1": 0,
    "-1": 0,
    "laugh": 0,
    "hooray": 0,
    "confused": 0,
    "heart": 0,
    "rocket": 0,
    "eyes": 0
}
Don't show foreign key links to tables the user cannot access 1886350562  
1710565268 https://github.com/simonw/datasette/issues/2178#issuecomment-1710565268 https://api.github.com/repos/simonw/datasette/issues/2178 IC_kwDOBm6k_c5l9SeU simonw 9599 2023-09-07T17:58:04Z 2023-09-07T17:59:06Z OWNER

Relevant code: https://github.com/simonw/datasette/blob/fbcb103c0cb6668018ace539a01a6a1f156e8d6a/datasette/views/table.py#L1132-L1149

Which calls this undocumented method:

https://github.com/simonw/datasette/blob/fbcb103c0cb6668018ace539a01a6a1f156e8d6a/datasette/app.py#L938-L973

{
    "total_count": 0,
    "+1": 0,
    "-1": 0,
    "laugh": 0,
    "hooray": 0,
    "confused": 0,
    "heart": 0,
    "rocket": 0,
    "eyes": 0
}
Don't show foreign key links to tables the user cannot access 1886350562  

Advanced export

JSON shape: default, array, newline-delimited, object

CSV options:

CREATE TABLE [issue_comments] (
   [html_url] TEXT,
   [issue_url] TEXT,
   [id] INTEGER PRIMARY KEY,
   [node_id] TEXT,
   [user] INTEGER REFERENCES [users]([id]),
   [created_at] TEXT,
   [updated_at] TEXT,
   [author_association] TEXT,
   [body] TEXT,
   [reactions] TEXT,
   [issue] INTEGER REFERENCES [issues]([id])
, [performed_via_github_app] TEXT);
CREATE INDEX [idx_issue_comments_issue]
                ON [issue_comments] ([issue]);
CREATE INDEX [idx_issue_comments_user]
                ON [issue_comments] ([user]);
Powered by Datasette · Queries took 23.04ms · About: github-to-sqlite
  • Sort ascending
  • Sort descending
  • Facet by this
  • Hide this column
  • Show all columns
  • Show not-blank rows