You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Superset配置AWS Cognito认证报错,求解决方案

解决Apache Superset与AWS Cognito认证的unsupported_grant_type错误

核心问题定位

unsupported_grant_type错误说明Superset向Cognito Token端点发送请求时,使用了Cognito不支持的授权类型。对于SSO常用的授权码流,Cognito仅接受authorization_code作为grant_type参数值,大概率是配置中该参数设置错误,或缺少必要的请求参数。

具体修复步骤

1. 检查自定义Security Manager的授权类型设置

确保在获取token的请求中,grant_type明确设置为authorization_code,同时包含code、redirect_uri、client_id、client_secret这些必填参数。示例代码片段:

def get_oauth_token(self, code):
    data = {
        'grant_type': 'authorization_code',  # 必须为该值
        'code': code,
        'redirect_uri': self.oauth_redirect_uri,
        'client_id': self.client_id,
        'client_secret': self.client_secret,
    }
    response = requests.post(self.token_url, data=data)
    response.raise_for_status()
    return response.json()

2. 验证Superset配置文件的OAuth参数

在superset_config.py中,确认以下参数配置正确:

  • token_url为Cognito的Token端点,格式为https://<你的用户池域名>/oauth2/token
  • redirect_uri必须与Cognito应用客户端中配置的回调地址完全一致(包含协议、域名、端口,无拼写/格式错误)
  • client_id和client_secret对应Cognito应用客户端的凭证
  • 确保scopes包含openid(Cognito认证必需)

示例配置片段:

OAUTH_PROVIDERS = [
    {
        'name': 'cognito',
        'token_url': 'https://your-cognito-domain.auth.us-east-1.amazoncognito.com/oauth2/token',
        'authorize_url': 'https://your-cognito-domain.auth.us-east-1.amazoncognito.com/oauth2/authorize',
        'client_id': 'your-client-id',
        'client_secret': 'your-client-secret',
        'redirect_uri': 'https://your-superset-domain.com/oauth-authorized/cognito',
        'scopes': ['openid', 'email', 'profile'],
    }
]

3. 检查Cognito应用客户端设置

  • 登录AWS控制台,进入Cognito用户池 → 应用客户端 → 编辑应用客户端
  • 确认授权类型中勾选了Authorization code grant
  • 验证回调URL与Superset配置的redirect_uri完全匹配
  • 测试环境下若使用HTTP,需开启允许HTTP流量选项(生产环境必须用HTTPS)

4. 排查请求参数是否被篡改

可在自定义Security Manager中添加日志,打印发送给Cognito的请求数据,确认参数无误:

import logging
logger = logging.getLogger(__name__)

def get_oauth_token(self, code):
    data = {
        'grant_type': 'authorization_code',
        'code': code,
        'redirect_uri': self.oauth_redirect_uri,
        'client_id': self.client_id,
        'client_secret': self.client_secret,
    }
    logger.info(f"Token请求参数: {data}")
    response = requests.post(self.token_url, data=data)
    logger.info(f"Token响应状态: {response.status_code}, 内容: {response.text}")
    response.raise_for_status()
    return response.json()

5. 确认Cognito端点正确性

确保token_url是Cognito的OAuth2 Token端点,不要混淆为用户池API端点或其他URL。

验证修复

修改配置后重启Superset服务,重新发起登录:

  1. 正常跳转到Cognito登录页,完成账号验证后跳转回Superset
  2. 查看日志无unsupported_grant_type错误
  3. 成功进入Superset仪表盘,说明认证流程正常

内容的提问来源于stack exchange,提问作者Gaurav Pareek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 10:52:22