Apache Superset配置AWS Cognito认证报错,求解决方案
解决Apache Superset与AWS Cognito认证的
unsupported_grant_type错误 核心问题定位
unsupported_grant_type错误说明Superset向Cognito Token端点发送请求时,使用了Cognito不支持的授权类型。对于SSO常用的授权码流,Cognito仅接受authorization_code作为grant_type参数值,大概率是配置中该参数设置错误,或缺少必要的请求参数。
具体修复步骤
1. 检查自定义Security Manager的授权类型设置
确保在获取token的请求中,grant_type明确设置为authorization_code,同时包含code、redirect_uri、client_id、client_secret这些必填参数。示例代码片段:
def get_oauth_token(self, code): data = { 'grant_type': 'authorization_code', # 必须为该值 'code': code, 'redirect_uri': self.oauth_redirect_uri, 'client_id': self.client_id, 'client_secret': self.client_secret, } response = requests.post(self.token_url, data=data) response.raise_for_status() return response.json()
2. 验证Superset配置文件的OAuth参数
在superset_config.py中,确认以下参数配置正确:
token_url为Cognito的Token端点,格式为https://<你的用户池域名>/oauth2/tokenredirect_uri必须与Cognito应用客户端中配置的回调地址完全一致(包含协议、域名、端口,无拼写/格式错误)client_id和client_secret对应Cognito应用客户端的凭证- 确保
scopes包含openid(Cognito认证必需)
示例配置片段:
OAUTH_PROVIDERS = [ { 'name': 'cognito', 'token_url': 'https://your-cognito-domain.auth.us-east-1.amazoncognito.com/oauth2/token', 'authorize_url': 'https://your-cognito-domain.auth.us-east-1.amazoncognito.com/oauth2/authorize', 'client_id': 'your-client-id', 'client_secret': 'your-client-secret', 'redirect_uri': 'https://your-superset-domain.com/oauth-authorized/cognito', 'scopes': ['openid', 'email', 'profile'], } ]
3. 检查Cognito应用客户端设置
- 登录AWS控制台,进入Cognito用户池 → 应用客户端 → 编辑应用客户端
- 确认授权类型中勾选了
Authorization code grant - 验证回调URL与Superset配置的
redirect_uri完全匹配 - 测试环境下若使用HTTP,需开启
允许HTTP流量选项(生产环境必须用HTTPS)
4. 排查请求参数是否被篡改
可在自定义Security Manager中添加日志,打印发送给Cognito的请求数据,确认参数无误:
import logging logger = logging.getLogger(__name__) def get_oauth_token(self, code): data = { 'grant_type': 'authorization_code', 'code': code, 'redirect_uri': self.oauth_redirect_uri, 'client_id': self.client_id, 'client_secret': self.client_secret, } logger.info(f"Token请求参数: {data}") response = requests.post(self.token_url, data=data) logger.info(f"Token响应状态: {response.status_code}, 内容: {response.text}") response.raise_for_status() return response.json()
5. 确认Cognito端点正确性
确保token_url是Cognito的OAuth2 Token端点,不要混淆为用户池API端点或其他URL。
验证修复
修改配置后重启Superset服务,重新发起登录:
- 正常跳转到Cognito登录页,完成账号验证后跳转回Superset
- 查看日志无
unsupported_grant_type错误 - 成功进入Superset仪表盘,说明认证流程正常
内容的提问来源于stack exchange,提问作者Gaurav Pareek
相关产品推荐
相关产品推荐

