diff --git a/UPDATING.md b/UPDATING.md index cd4cdf92e..2112fe60d 100644 --- a/UPDATING.md +++ b/UPDATING.md @@ -23,6 +23,8 @@ This file documents any backwards-incompatible changes in Superset and assists people when migrating to a new version. ## Next + +- [24185](https://github.com/apache/superset/pull/24185): `/api/v1/database/test_connection` and `api/v1/database/validate_parameters` permissions changed from `can_read` to `can_write`. Only Admin user's have access. - [24256](https://github.com/apache/superset/pull/24256): `Flask-Login` session validation is now set to `strong` by default. Previous setting was `basic`. - [24232](https://github.com/apache/superset/pull/24232): Enables ENABLE_TEMPLATE_REMOVE_FILTERS, DRILL_TO_DETAIL, DASHBOARD_CROSS_FILTERS by default, marks VERSIONED_EXPORT and ENABLE_TEMPLATE_REMOVE_FILTERS as deprecated. - [23652](https://github.com/apache/superset/pull/23652): Enables GENERIC_CHART_AXES feature flag by default. diff --git a/superset/constants.py b/superset/constants.py index e4bad9f8a..063cd5f22 100644 --- a/superset/constants.py +++ b/superset/constants.py @@ -125,8 +125,8 @@ MODEL_API_RW_METHOD_PERMISSION_MAP = { "select_star": "read", "table_metadata": "read", "table_extra_metadata": "read", - "test_connection": "read", - "validate_parameters": "read", + "test_connection": "write", + "validate_parameters": "write", "favorite_status": "read", "add_favorite": "read", "remove_favorite": "read",