Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
aa1a695
fix(mcp): prevent GRID_ID injection into ROOT_ID on tabbed dashboards…
aminghadersohi Mar 30, 2026
89f7e5e
fix(mcp): validate dataset exists in generate_explore_link before gen…
aminghadersohi Mar 30, 2026
41d401a
fix(select): ensure filter dropdown matches input field width (#38886)
EnxDev Mar 30, 2026
d331a04
fix(mcp): prevent PendingRollbackError from poisoned sessions after S…
aminghadersohi Mar 30, 2026
15bab22
feat(mcp): support saved metrics from datasets in chart generation (#…
kgabryje Mar 30, 2026
38fdfb4
fix(mcp): prevent stale g.user from causing user impersonation across…
aminghadersohi Mar 30, 2026
2c9cf0b
fix(mcp): enforce MAX_PAGE_SIZE limit on list tools to prevent oversi…
aminghadersohi Mar 30, 2026
e0a0a22
fix(charts): add X Axis Number Format control for numeric X-axis colu…
EnxDev Mar 31, 2026
f1cd1ae
fix(pivot-table): safely cast numeric strings to numbers for date for…
michael-s-molina Mar 31, 2026
11f2140
fix(AlteredSliceTag): not display undefined filter value for chart ch…
hainenber Mar 31, 2026
b49e899
chore(deps-dev): bump typescript-eslint from 8.57.2 to 8.58.0 in /doc…
dependabot[bot] Mar 31, 2026
b1474aa
docs: Fix misleading links in UPDATING.md (#38947)
torzsmokus Mar 31, 2026
ecbf396
chore(deps): bump path-to-regexp from 8.2.0 to 8.4.0 in /superset-web…
dependabot[bot] Mar 31, 2026
944944c
chore(deps): bump antd from 6.3.4 to 6.3.5 in /docs (#38967)
dependabot[bot] Mar 31, 2026
e6f1209
chore(deps): bump aws-actions/amazon-ecr-login from 2.0.2 to 2.1.1 (#…
dependabot[bot] Mar 31, 2026
f0b20dc
fix(echarts): adapt y-axis ticks and padding for compact timeseries c…
EnxDev Mar 31, 2026
4245720
feat(mcp): add Big Number chart type support to MCP service (#38403)
aminghadersohi Mar 31, 2026
c37a3ec
fix(mcp): add TEMPORAL_RANGE filter for temporal x-axis in generate_c…
aminghadersohi Mar 31, 2026
daefede
fix(mcp): batch fix for execute_sql crashes, null timestamps, and dec…
aminghadersohi Mar 31, 2026
f6cd806
fix(bubble): Fix Bubble chart axis label rotation (#38917)
cyber-jessie Mar 31, 2026
7d26e33
chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 in /superset-webs…
dependabot[bot] Mar 31, 2026
a741ddc
chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 in /superset-embe…
dependabot[bot] Mar 31, 2026
3abcfb7
chore(deps-dev): bump open-cli from 8.0.0 to 9.0.0 in /superset-front…
dependabot[bot] Mar 31, 2026
55aa36f
docs(developer): add celery to testing section for alerts&reports (#3…
msyavuz Mar 31, 2026
53b1d10
fix(presto): Fix presto timestamp (#26467)
zhaorui2022 Mar 31, 2026
e4021fb
fix(sec): resolve 50+ Dependabot alerts + bump `core-js` (#38939)
dependabot[bot] Mar 31, 2026
08a4ad6
chore(deps): bump brace-expansion from 1.1.11 to 1.1.13 in /superset-…
dependabot[bot] Mar 31, 2026
4036b78
chore(deps): bump serialize-javascript and terser-webpack-plugin in /…
dependabot[bot] Mar 31, 2026
6ea9f2a
chore(mcp): clarify saved metrics vs columns in MCP instructions (#38…
kgabryje Mar 31, 2026
f85efe6
chore(build): remove eslint-plugin-file-progress usage + correct newl…
dependabot[bot] Mar 31, 2026
4fae575
chore(deps): bump baseline-browser-mapping from 2.10.11 to 2.10.12 in…
dependabot[bot] Mar 31, 2026
d4d2290
fix(dashboard): live CSS preview in PropertiesModal (#38960)
michael-s-molina Mar 31, 2026
8559786
fix(mixed-timeseries): apply same axis formatting options as timeseri…
michael-s-molina Mar 31, 2026
1e2d0fa
fix(dashboard): dashboard filters not inherited in charts in Safari s…
madhushreeag Mar 31, 2026
64bd03b
chore(deps): bump caniuse-lite from 1.0.30001781 to 1.0.30001782 in /…
dependabot[bot] Apr 1, 2026
872632a
chore(deps): bump fs-extra from 11.3.2 to 11.3.4 in /superset-fronten…
dependabot[bot] Apr 1, 2026
7ce3710
chore(deps-dev): bump @types/node from 25.3.3 to 25.3.5 in /superset-…
dependabot[bot] Apr 1, 2026
bd98269
chore(deps): bump hot-shots from 14.1.1 to 14.2.0 in /superset-websoc…
dependabot[bot] Apr 1, 2026
070be3d
chore(deps-dev): bump webpack-bundle-analyzer from 5.2.0 to 5.3.0 in …
dependabot[bot] Apr 1, 2026
424f99e
chore(deps): bump anthropics/claude-code-action from 1.0.80 to 1.0.82…
dependabot[bot] Apr 1, 2026
51ec61c
chore(deps-dev): bump eslint from 10.0.2 to 10.0.3 in /superset-webso…
dependabot[bot] Apr 1, 2026
6b6e380
chore(deps-dev): bump @typescript-eslint/eslint-plugin from 8.56.1 to…
dependabot[bot] Apr 1, 2026
a67ca05
chore(deps-dev): bump babel-loader from 10.0.0 to 10.1.0 in /superset…
dependabot[bot] Apr 1, 2026
4ee391e
docs(db): Update crate.py with new Homepage URL (#39002)
michaelkremmel Apr 1, 2026
8ed7578
chore(deps-dev): bump jsdom from 28.1.0 to 29.0.1 in /superset-fronte…
dependabot[bot] Apr 1, 2026
d30c5b4
chore(deps): bump caniuse-lite from 1.0.30001782 to 1.0.30001784 in /…
dependabot[bot] Apr 1, 2026
64c8d65
chore(deps-dev): bump @types/node from 25.3.5 to 25.5.0 in /superset-…
dependabot[bot] Apr 1, 2026
94d8735
fix(query): pass datasource table to template processor for schema-aw…
michael-s-molina Apr 1, 2026
aa97679
chore(deps): update @deck.gl/aggregation-layers requirement from ~9.2…
dependabot[bot] Apr 1, 2026
6adc816
chore(deps): bump d3-cloud from 1.2.8 to 1.2.9 in /superset-frontend …
dependabot[bot] Apr 1, 2026
5f99d61
chore(deps): bump markdown-to-jsx from 9.7.6 to 9.7.8 in /superset-fr…
dependabot[bot] Apr 1, 2026
190f1a5
fix(mcp): fix dashboard owners Pydantic crash and preserve chart prev…
aminghadersohi Apr 1, 2026
4423134
chore(deps): bump ioredis from 5.10.0 to 5.10.1 in /superset-websocke…
dependabot[bot] Apr 1, 2026
1bb41a6
chore(deps): bump anthropics/claude-code-action from 1.0.82 to 1.0.83…
dependabot[bot] Apr 1, 2026
0bae05d
fix(mcp): handle table chart raw mode in query builders and sanitize …
aminghadersohi Apr 1, 2026
38f0dc7
fix(dataset-editor): improve modal layout and fix Settings tab horizo…
michael-s-molina Apr 1, 2026
0223428
fix(echarts): fix stacked horizontal bar chart clipping and duplicate…
michael-s-molina Apr 1, 2026
ff3b8d8
fix(ace-editor): fix cursor misalignment in markdown editor (#38928)
cyphercodes Apr 1, 2026
ec6640b
chore(deps-dev): update fs-extra requirement from ^11.3.3 to ^11.3.4 …
dependabot[bot] Apr 1, 2026
1d0e836
chore(deps): update @deck.gl/extensions requirement from ~9.2.5 to ~9…
dependabot[bot] Apr 1, 2026
00eb86d
chore(deps-dev): bump @swc/plugin-emotion from 14.6.0 to 14.7.0 in /s…
dependabot[bot] Apr 1, 2026
7acb0c6
chore(deps-dev): bump @types/node from 25.3.3 to 25.3.5 in /superset-…
dependabot[bot] Apr 1, 2026
9771cd3
fix: add allowlist to TabStateView.put
sha174n Apr 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/claude.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
fetch-depth: 1

- name: Run Claude PR Action
uses: anthropics/claude-code-action@094bd24d575e7b30ac1576024817bf1a97c81262 # beta
uses: anthropics/claude-code-action@bee87b3258c251f9279e5371b0cc3660f37f3f77 # beta
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
timeout_minutes: "60"
4 changes: 2 additions & 2 deletions .github/workflows/ephemeral-env.yml
Original file line number Diff line number Diff line change
Expand Up @@ -199,7 +199,7 @@ jobs:

- name: Login to Amazon ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@c962da2960ed15f492addc26fffa274485265950 # v2
uses: aws-actions/amazon-ecr-login@183a1442edf41672e66566b7fc560e297a290896 # v2

- name: Load, tag and push image to ECR
id: push-image
Expand Down Expand Up @@ -235,7 +235,7 @@ jobs:

- name: Login to Amazon ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@c962da2960ed15f492addc26fffa274485265950 # v2
uses: aws-actions/amazon-ecr-login@183a1442edf41672e66566b7fc560e297a290896 # v2

- name: Check target image exists in ECR
id: check-image
Expand Down
4 changes: 2 additions & 2 deletions UPDATING.md
Original file line number Diff line number Diff line change
Expand Up @@ -308,13 +308,13 @@ Note: Pillow is now a required dependency (previously optional) to support image
There's a migration added that can potentially affect a significant number of existing charts.
- [32317](https://github.com/apache/superset/pull/32317) The horizontal filter bar feature is now out of testing/beta development and its feature flag `HORIZONTAL_FILTER_BAR` has been removed.
- [31590](https://github.com/apache/superset/pull/31590) Marks the begining of intricate work around supporting dynamic Theming, and breaks support for [THEME_OVERRIDES](https://github.com/apache/superset/blob/732de4ac7fae88e29b7f123b6cbb2d7cd411b0e4/superset/config.py#L671) in favor of a new theming system based on AntD V5. Likely this will be in disrepair until settling over the 5.x lifecycle.
- [32432](https://github.com/apache/superset/pull/31260) Moves the List Roles FAB view to the frontend and requires `FAB_ADD_SECURITY_API` to be enabled in the configuration and `superset init` to be executed.
- [32432](https://github.com/apache/superset/pull/32432) Moves the List Roles FAB view to the frontend and requires `FAB_ADD_SECURITY_API` to be enabled in the configuration and `superset init` to be executed.
- [34319](https://github.com/apache/superset/pull/34319) Drill to Detail and Drill By is now supported in Embedded mode, and also with the `DASHBOARD_RBAC` FF. If you don't want to expose these features in Embedded / `DASHBOARD_RBAC`, make sure the roles used for Embedded / `DASHBOARD_RBAC`don't have the required permissions to perform D2D actions.

## 5.0.0

- [31976](https://github.com/apache/superset/pull/31976) Removed the `DISABLE_LEGACY_DATASOURCE_EDITOR` feature flag. The previous value of the feature flag was `True` and now the feature is permanently removed.
- [31959](https://github.com/apache/superset/pull/32000) Removes CSV_UPLOAD_MAX_SIZE config, use your web server to control file upload size.
- [32000](https://github.com/apache/superset/pull/32000) Removes CSV_UPLOAD_MAX_SIZE config, use your web server to control file upload size.
- [31959](https://github.com/apache/superset/pull/31959) Removes the following endpoints from data uploads: `/api/v1/database/<id>/<file type>_upload` and `/api/v1/database/<file type>_metadata`, in favour of new one (Details on the PR). And simplifies permissions.
- [31844](https://github.com/apache/superset/pull/31844) The `ALERT_REPORTS_EXECUTE_AS` and `THUMBNAILS_EXECUTE_AS` config parameters have been renamed to `ALERT_REPORTS_EXECUTORS` and `THUMBNAILS_EXECUTORS` respectively. A new config flag `CACHE_WARMUP_EXECUTORS` has also been introduced to be able to control which user is used to execute cache warmup tasks. Finally, the config flag `THUMBNAILS_SELENIUM_USER` has been removed. To use a fixed executor for async tasks, use the new `FixedExecutor` class. See the config and docs for more info on setting up different executor profiles.
- [31894](https://github.com/apache/superset/pull/31894) Domain sharding is deprecated in favor of HTTP2. The `SUPERSET_WEBSERVER_DOMAINS` configuration will be removed in the next major version (6.0)
Expand Down
103 changes: 103 additions & 0 deletions docs/developer_docs/testing/backend-testing.md
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,109 @@ pytest tests/unit_tests/
pytest tests/integration_tests/
```

## Testing Alerts & Reports with Celery and MailHog

The Alerts & Reports feature relies on Celery for task scheduling and execution. To test it locally, you need Redis (message broker), Celery Beat (scheduler), a Celery Worker (executor), and an SMTP server to receive email notifications.

### Prerequisites

- Redis running on `localhost:6379`
- [MailHog](https://github.com/mailhog/MailHog) installed (a local SMTP server with a web UI for viewing caught emails)

### superset_config.py

Your `CeleryConfig` **must** include `beat_schedule`. When you define a custom `CeleryConfig` class in `superset_config.py`, it replaces the default entirely. If you omit `beat_schedule`, Celery Beat will start but never schedule any report tasks.

```python
from celery.schedules import crontab
from superset.tasks.types import ExecutorType

REDIS_HOST = "localhost"
REDIS_PORT = "6379"

class CeleryConfig:
broker_url = f"redis://{REDIS_HOST}:{REDIS_PORT}/0"
result_backend = f"redis://{REDIS_HOST}:{REDIS_PORT}/0"
broker_connection_retry_on_startup = True
imports = (
"superset.sql_lab",
"superset.tasks.scheduler",
"superset.tasks.thumbnails",
"superset.tasks.cache",
)
worker_prefetch_multiplier = 10
task_acks_late = True
beat_schedule = {
"reports.scheduler": {
"task": "reports.scheduler",
"schedule": crontab(minute="*", hour="*"),
},
"reports.prune_log": {
"task": "reports.prune_log",
"schedule": crontab(minute=0, hour=0),
},
}

CELERY_CONFIG = CeleryConfig

# SMTP settings pointing to MailHog
SMTP_HOST = "localhost"
SMTP_PORT = 1025
SMTP_STARTTLS = False
SMTP_SSL = False
SMTP_USER = ""
SMTP_PASSWORD = ""
SMTP_MAIL_FROM = "superset@localhost"

# Must match where your frontend is running
WEBDRIVER_BASEURL = "http://localhost:9000/"

ALERT_REPORTS_EXECUTE_AS = [ExecutorType.OWNER]

FEATURE_FLAGS = {
"ALERT_REPORTS": True,
# Recommended for better screenshot support (WebGL/DeckGL charts)
"PLAYWRIGHT_REPORTS_AND_THUMBNAILS": True,
}
```

:::note
Do not include `"superset.tasks.async_queries"` in `CeleryConfig.imports` unless you need Global Async Queries. That module accesses `current_app.config` at import time and will crash the worker with a "Working outside of application context" error.
:::

### Starting the Services

Start MailHog, then Celery Beat and Worker in separate terminals:

```bash
# Terminal 1 - MailHog (SMTP on :1025, Web UI on :8025)
MailHog

# Terminal 2 - Celery Beat (scheduler)
celery --app=superset.tasks.celery_app:app beat --loglevel=info

# Terminal 3 - Celery Worker (executor)
celery --app=superset.tasks.celery_app:app worker --concurrency=1 --loglevel=info
```

Use `--concurrency=1` to limit resource usage on your dev machine.

### Verifying the Setup

1. **Beat** should log `Scheduler: Sending due task reports.scheduler (reports.scheduler)` once per minute
2. **Worker** should log `Scheduling alert <name> eta: <timestamp>` for each active report
3. Create a test report in **Settings > Alerts & Reports** with a `* * * * *` cron schedule
4. Check **http://localhost:8025** (MailHog web UI) for the email within 1-2 minutes

### Troubleshooting

| Problem | Solution |
|---|---|
| Beat shows no output | Ensure `beat_schedule` is defined in your `CeleryConfig` and `--loglevel=info` is set |
| "Report Schedule is still working, refusing to re-compute" | Previous executions are stuck. Reset with: `UPDATE report_schedule SET last_state = 'Not triggered' WHERE id = <id>;` |
| Task backlog overwhelming the worker | Flush Redis: `redis-cli FLUSHDB`, then restart Beat and Worker |
| Screenshot timeout | Ensure your frontend dev server is running and `WEBDRIVER_BASEURL` matches its URL |

---

*This documentation is under active development. Check back soon for updates!*
8 changes: 4 additions & 4 deletions docs/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -68,9 +68,9 @@
"@storybook/theming": "^8.6.15",
"@superset-ui/core": "^0.20.4",
"@swc/core": "^1.15.21",
"antd": "^6.3.4",
"baseline-browser-mapping": "^2.10.11",
"caniuse-lite": "^1.0.30001781",
"antd": "^6.3.5",
"baseline-browser-mapping": "^2.10.13",
"caniuse-lite": "^1.0.30001784",
"docusaurus-plugin-openapi-docs": "^4.6.0",
"docusaurus-theme-openapi-docs": "^4.6.0",
"js-yaml": "^4.1.1",
Expand Down Expand Up @@ -106,7 +106,7 @@
"globals": "^17.4.0",
"prettier": "^3.8.1",
"typescript": "~5.9.3",
"typescript-eslint": "^8.57.2",
"typescript-eslint": "^8.58.0",
"webpack": "^5.105.4"
},
"browserslist": {
Expand Down
Loading
Loading