Docker部署Superset配置Google SSO登录失败求助
问题
通过Docker安装Superset后,按照官方文档配置Google SSO登录,修改了superset_config.py并创建了custom_sso_security_manager.py,但Google SSO页面打开后,输入账号密码提示「Invalid login.Please try again」。本地服务使用HTTP而非HTTPS,配置细节如下:
现有superset_config.py配置
# Set the authentication type to OAuth AUTH_TYPE = AUTH_OAUTH from custom_sso_security_manager import CustomSsoSecurityManager CUSTOM_SECURITY_MANAGER = CustomSsoSecurityManager OAUTH_PROVIDERS = [ { 'name':'google', 'token_key':'access_token', # Name of the token in the response of access_token_url 'icon':'fa-address-card', # Icon for the provider 'remote_app': { 'client_id':'clientIdfromCredintials', # Client Id (Identify Superset application) 'client_secret':'clientsecretfromCredintials', # Secret for this Client Id (Identify Superset application) 'client_kwargs':{ 'scope': 'email profile' # Scope for the Authorization }, 'access_token_method':'POST', # HTTP Method to call access_token_url 'access_token_params':{ # Additional parameters for calls to access_token_url 'client_id':'clientIdfromCredintials' }, 'access_token_headers':{ # Additional headers for calls to access_token_url 'Authorization': 'Basic XXXX' }, 'api_base_url':'https://www.googleapis.com/oauth2/v2/', 'access_token_url':'https://accounts.google.com/o/oauth2/token', 'authorize_url':'https://accounts.google.com/o/oauth2/auth' }, 'request_token_params': { 'response_type': 'code', 'scope': 'email profile' } } ]
现有custom_sso_security_manager.py代码
import logging from superset.security import SupersetSecurityManager class CustomSsoSecurityManager(SupersetSecurityManager): def oauth_user_info(self, provider, response=None): logging.debug("Oauth2 provider: {0}.".format(provider)) if provider == 'google': # As example, this line request a GET to base_url + '/' + userDetails with Bearer Authentication, # and expects that authorization server checks the token, and response with user details me = self.appbuilder.sm.oauth_remotes[provider].get('userDetails').data logging.debug("user_data: {0}".format(me)) return { 'name' : me['name'], 'email' : me['email'], 'id' : me['user_name'], 'username' : me['user_name'], 'first_name':'', 'last_name':''}
谷歌云控制台配置重定向URL时,尝试过https://<superset-webserver>/oauth-authorized/google和http://localhost:8088/superset/welcome,均未解决问题。
问题排查与修正方案
1. 重定向URL配置错误
Superset OAuth的正确重定向URL格式为http://<your-superset-host>:<port>/oauth-authorized/<provider-name>,针对本地HTTP服务,应配置为http://localhost:8088/oauth-authorized/google。
在谷歌云控制台的OAuth 2.0客户端ID设置中,确保仅保留此正确的重定向URL,删除其他无效的URL(如/superset/welcome)。
2. 多余的Basic Auth头与重复参数
Google OAuth获取access_token时,不需要额外的Authorization: Basic XXXX头,且remote_app中已配置client_id,无需在access_token_params中重复填写。
修改superset_config.py中的remote_app部分,删除冗余配置:
'remote_app': { 'client_id':'clientIdfromCredintials', 'client_secret':'clientsecretfromCredintials', 'client_kwargs':{ 'scope': 'email profile' }, 'access_token_method':'POST', 'api_base_url':'https://www.googleapis.com/oauth2/v2/', 'access_token_url':'https://accounts.google.com/o/oauth2/token', 'authorize_url':'https://accounts.google.com/o/oauth2/auth' },
3. 用户信息API端点错误
Google OAuth的用户信息端点是userinfo而非userDetails,且返回字段中没有user_name,应使用id或email作为用户标识。
修改custom_sso_security_manager.py的oauth_user_info方法:
import logging from superset.security import SupersetSecurityManager class CustomSsoSecurityManager(SupersetSecurityManager): def oauth_user_info(self, provider, response=None): logging.debug("Oauth2 provider: {0}.".format(provider)) if provider == 'google': me = self.appbuilder.sm.oauth_remotes[provider].get('userinfo').data logging.debug("user_data: {0}".format(me)) # 从返回的用户信息中提取正确字段,谷歌返回的字段包括name、email、id等 return { 'name': me['name'], 'email': me['email'], 'id': me['id'], 'username': me['email'], # 用邮箱作为用户名 'first_name': me.get('given_name', ''), 'last_name': me.get('family_name', '') }
4. 确保Docker容器加载自定义配置
如果是通过Docker部署,需确保superset_config.py和custom_sso_security_manager.py已挂载到容器的正确路径(通常是/app/pythonpath/superset_config.py),并重启Superset容器使配置生效。
内容的提问来源于stack exchange,提问作者AB21

