You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Superset配置Microsoft SSO后登录失败(含404错误)

Superset Microsoft SSO登录重定向失败问题

我在AWS EC2实例上通过Docker Compose部署了Superset,执行docker compose up后服务正常启动。为Superset配置了Microsoft SSO登录功能,预期流程是用户进入Superset登录页,输入Microsoft凭证完成验证后跳转至Superset系统内部。但实际情况是用户验证成功后,被重定向回登录页并提示**‘Invalid login. Please try again’,且superset_app容器日志显示‘werkzeug.exceptions.NotFound: 404 Not Found: The requested URL was not found on the server’**。

我的superset_config.py配置文件

import logging
import os

from celery.schedules import crontab
from flask_caching.backends.filesystemcache import FileSystemCache

logger = logging.getLogger()

DATABASE_DIALECT = os.getenv("DATABASE_DIALECT")
DATABASE_USER = os.getenv("DATABASE_USER")
DATABASE_PASSWORD = os.getenv("DATABASE_PASSWORD")
DATABASE_HOST = os.getenv("DATABASE_HOST")
DATABASE_PORT = os.getenv("DATABASE_PORT")
DATABASE_DB = os.getenv("DATABASE_DB")

EXAMPLES_USER = os.getenv("EXAMPLES_USER")
EXAMPLES_PASSWORD = os.getenv("EXAMPLES_PASSWORD")
EXAMPLES_HOST = os.getenv("EXAMPLES_HOST")
EXAMPLES_PORT = os.getenv("EXAMPLES_PORT")
EXAMPLES_DB = os.getenv("EXAMPLES_DB")

# The SQLAlchemy connection string.
SQLALCHEMY_DATABASE_URI = (
    f"{DATABASE_DIALECT}://"
    f"{DATABASE_USER}:{DATABASE_PASSWORD}@"
    f"{DATABASE_HOST}:{DATABASE_PORT}/{DATABASE_DB}"
)

SQLALCHEMY_EXAMPLES_URI = (
    f"{DATABASE_DIALECT}://"
    f"{EXAMPLES_USER}:{EXAMPLES_PASSWORD}@"
    f"{EXAMPLES_HOST}:{EXAMPLES_PORT}/{EXAMPLES_DB}"
)

REDIS_HOST = os.getenv("REDIS_HOST", "redis")
REDIS_PORT = os.getenv("REDIS_PORT", "6379")
REDIS_CELERY_DB = os.getenv("REDIS_CELERY_DB", "0")
REDIS_RESULTS_DB = os.getenv("REDIS_RESULTS_DB", "1")

RESULTS_BACKEND = FileSystemCache("/app/superset_home/sqllab")

CACHE_CONFIG = {
    "CACHE_TYPE": "RedisCache",
    "CACHE_DEFAULT_TIMEOUT": 300,
    "CACHE_KEY_PREFIX": "superset_",
    "CACHE_REDIS_HOST": REDIS_HOST,
    "CACHE_REDIS_PORT": REDIS_PORT,
    "CACHE_REDIS_DB": REDIS_RESULTS_DB,
}
DATA_CACHE_CONFIG = CACHE_CONFIG


class CeleryConfig:
    broker_url = f"redis://{REDIS_HOST}:{REDIS_PORT}/{REDIS_CELERY_DB}"
    imports = (
        "superset.sql_lab",
        "superset.tasks.scheduler",
        "superset.tasks.thumbnails",
        "superset.tasks.cache",
    )
    result_backend = f"redis://{REDIS_HOST}:{REDIS_PORT}/{REDIS_RESULTS_DB}"
    worker_prefetch_multiplier = 1
    task_acks_late = False
    beat_schedule = {
        "reports.scheduler": {
            "task": "reports.scheduler",
            "schedule": crontab(minute="*", hour="*"),
        },
        "reports.prune_log": {
            "task": "reports.prune_log",
            "schedule": crontab(minute=10, hour=0),
        },
    }


CELERY_CONFIG = CeleryConfig

FEATURE_FLAGS = {"ALERT_REPORTS": True}
ALERT_REPORTS_NOTIFICATION_DRY_RUN = True
# When using docker compose baseurl should be http://superset_app:8088/
# The base URL for the email report hyperlinks.
SQLLAB_CTAS_NO_LIMIT = True

#
# Optionally import superset_config_docker.py (which will have been included on
# the PYTHONPATH) in order to allow for local settings to be overridden
#
try:
    import superset_config_docker
    from superset_config_docker import *  # noqa

    logger.info(
        f"Loaded your Docker configuration at " f"[{superset_config_docker.__file__}]"
    )
except ImportError:
    logger.info("Using default Docker config...")

# Ensure you are using HTTPS
ENABLE_PROXY_FIX = True
PREFERRED_URL_SCHEME = 'https'
SESSION_COOKIE_HTTPONLY = "Lax"

#SSO Login
from flask_appbuilder.security.manager import AUTH_OAUTH
from custom_sso_security_manager import CustomSsoSecurityManager

# Set the authentication type to OAuth
AUTH_TYPE = AUTH_OAUTH

# Will allow user self registration, allowing to create Flask users from Authorized User
AUTH_USER_REGISTRATION = True

# The default user self registration role
AUTH_USER_REGISTRATION_ROLE = "Public"
CUSTOM_SECURITY_MANAGER = CustomSsoSecurityManager

OAUTH_PROVIDERS = [{
   'name': 'SSO',
   'token_key': 'access_token',
   'icon': 'fa-windows',
   'remote_app':{
        'api_base_url': 'https://login.microsoft.com/tenant_id/oauth2',
        'request_token_url': None,
        'request_token_params': {
                'scope': 'openid profile email'
        },
        'access_token_url': 'https://login.microsoftonline.com/tenant_id/oauth2/v2.0/token',
        'acess_token_params':{
                'scope': 'openid profile email'
        },
        'authorize_url': 'https://login.microsoftonline.com/tenant_id/oauth2/v2.0/authorize',
        'authorize_params':{
                'scope': 'openid profile email'
        },
        'client_id': 'client-id(application-id)',
        'client_secret': 'secret-key',
        'jwks_uri': 'https://login.microsoftonline.com/common/discovery/v2.0/keys',
        'redirect_uri': 'https://superset.domain.com/oauth-authorize/callback'
   }
}]

OAUTH_USER_INFO_URL = 'https://graph.microsoft.com/v1.0/me'

from flask_appbuilder.security.manager import AUTH_OAUTH

def get_oauth_user_info(response):
    user_info = response.json()

    # Assign role based on domain
    if user_info['mail'].endswith('@domain.com'):
        return {
            'role': 'Admin',
            'user_info': user_info
        }
    else:
        return {
            'role': 'Public',
            'user_info': user_info
        }

已尝试的排查步骤

  • 检查应用(客户端)ID
  • 检查密钥
  • 检查配置文件

已确认这是Superset仓库中的公开问题,尝试了该问题评论区的解决方案,同时严格遵循官方Docker Compose部署文档配置docker-compose.yaml,但问题仍未解决。

内容的提问来源于stack exchange,提问作者RushHour

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 08:09:58