You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Superset集成IBM APPID OAuth2登录失败排查求助

配置Apache Superset对接IBM APPID的OAuth2认证问题排查

问题描述

尝试为Apache Superset配置OAuth2认证对接IBM APPID,登录时能正常跳转到OAuth服务完成认证,但返回Superset后提示Invalid login. Please try again.,自定义安全管理器中的日志语句未输出,日志显示Error returning OAuth user info: 'oauth_token'。

Superset配置文件 (superset_config.py)

from flask_appbuilder.security.manager import AUTH_OAUTH

LOG_LEVEL = "DEBUG"

FEATURE_FLAGS = {
    "ENABLE_TEMPLATE_PROCESSING": True,
}

ENABLE_PROXY_FIX = True
SECRET_KEY = "YOUR_OWN_RANDOM_GENERATED_STRING"

AUTH_TYPE = AUTH_OAUTH
OAUTH_PROVIDERS = [
    {
        'name': 'appid',
        'icon': 'fa-address-card',
        'remote_app': {
            'client_id': 'client-id',
            'client_secret': 'shhhhhh',
            # 'client_kwargs': {
            #     'scope': 'read'  # Scope for the Authorization
            # },
            'server_metadata_url': 'https://eu-de.appid.cloud.ibm.com/oauth/v4/instance-id/.well-known/openid-configuration'
        }
    }
]
# AUTH_ROLE_ADMIN = 'Admin'

from custom_sso_security_manager import CustomSsoSecurityManager

CUSTOM_SECURITY_MANAGER = CustomSsoSecurityManager

# Will allow user self registration, allowing to create Flask users from Authorized User
AUTH_USER_REGISTRATION = True
# The default user self registration role
AUTH_USER_REGISTRATION_ROLE = "Public"

自定义Security Manager代码 (custom_sso_security_manager.py)

import logging
from superset.security import SupersetSecurityManager


class CustomSsoSecurityManager(SupersetSecurityManager):

    def oauth_user_info(self, provider, response=None):
        logging.error("CustomSsoSecurityManager Oauth2 provider: {0}.".format(provider))
        if provider == 'appid':
            # As example, this line request a GET to base_url + '/' + userDetails with Bearer  Authentication,
            # and expects that authorization server checks the token, and response with user details
            user_info_response = self.appbuilder.sm.oauth_remotes[provider].get('userinfo')
            logging.error("user_info_response: {0}".format(user_info_response))

            user_detail_response = (self.appbuilder.sm.oauth_remotes[provider].get('userDetails'))
            logging.error("user_detail_response: {0}".format(user_detail_response))

            me = user_detail_response.data
            logging.error("user_data: {0}".format(me))

            return {'name': me['name'], 'email': me['email'], 'id': me['user_name'], 'username': me['user_name'],
                    'first_name': '', 'last_name': ''}

错误日志

DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): eu-de.appid.cloud.ibm.com:443
DEBUG:urllib3.connectionpool:https://eu-de.appid.cloud.ibm.com:443 "POST /oauth/v4/instance-id/token HTTP/1.1" 200 None
ERROR:flask_appbuilder.security.views:Error returning OAuth user info: 'oauth_token'

排查建议

  • 确认自定义Security Manager加载状态

    • 确保custom_sso_security_manager.py放置在Superset能识别的Python路径中(例如与superset_config.py同目录,或添加到PYTHONPATH环境变量)
    • 在superset_config.py开头添加导入验证代码,比如import custom_sso_security_manager; print("Custom security manager loaded successfully"),启动Superset时查看控制台输出
    • 检查Superset启动日志,确认是否有加载自定义管理器的相关记录
  • 修复'oauth_token'错误

    • 启用OpenID Connect必需的scope:在OAUTH_PROVIDERS的client_kwargs中添加'scope': 'openid email profile',IBM APPID需要这些scope才能返回标准的用户信息和令牌
    • 手动调用IBM APPID的token端点,验证返回的响应格式是否符合OAuth2标准(应包含access_token、token_type等字段)
    • 检查IBM APPID控制台中配置的redirect_uri是否与Superset的回调地址完全一致,包括协议、域名、端口
  • 调试令牌获取流程

    • 临时提升Flask-AppBuilder的日志级别,在superset_config.py中添加FAB_LOG_LEVEL = "DEBUG",获取更详细的OAuth流程日志
    • 若允许调试,可修改Flask-AppBuilder的security/views.py,在报错位置添加日志打印完整的token响应,确认是否缺少oauth_token或相关字段
  • 验证用户信息端点正确性

    • 访问IBM APPID的well-known配置地址https://eu-de.appid.cloud.ibm.com/oauth/v4/instance-id/.well-known/openid-configuration,查看userinfo_endpoint的准确路径
    • 自定义方法中使用上述端点路径,不要硬编码userinfo或userDetails,确保请求的是正确的用户信息接口

内容的提问来源于stack exchange,提问作者Otrebor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 23:44:58