You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署Superset配置Google SSO登录失败求助

问题

通过Docker安装Superset后,按照官方文档配置Google SSO登录,修改了superset_config.py并创建了custom_sso_security_manager.py,但Google SSO页面打开后,输入账号密码提示「Invalid login.Please try again」。本地服务使用HTTP而非HTTPS,配置细节如下:

现有superset_config.py配置

# Set the authentication type to OAuth
AUTH_TYPE = AUTH_OAUTH

from custom_sso_security_manager import CustomSsoSecurityManager
CUSTOM_SECURITY_MANAGER = CustomSsoSecurityManager

OAUTH_PROVIDERS = [
    {   'name':'google',
        'token_key':'access_token', # Name of the token in the response of access_token_url
        'icon':'fa-address-card',   # Icon for the provider
        'remote_app': {
            'client_id':'clientIdfromCredintials',  # Client Id (Identify Superset application)
            'client_secret':'clientsecretfromCredintials', # Secret for this Client Id (Identify Superset application)
            'client_kwargs':{
                'scope': 'email profile'               # Scope for the Authorization
            },
            'access_token_method':'POST',    # HTTP Method to call access_token_url
            'access_token_params':{        # Additional parameters for calls to access_token_url
                'client_id':'clientIdfromCredintials'
            },
            'access_token_headers':{    # Additional headers for calls to access_token_url
                'Authorization': 'Basic XXXX'
            },
            'api_base_url':'https://www.googleapis.com/oauth2/v2/',
            'access_token_url':'https://accounts.google.com/o/oauth2/token',
            'authorize_url':'https://accounts.google.com/o/oauth2/auth'
        },
        'request_token_params': {
                'response_type': 'code',
                'scope': 'email profile'
            }
            
    }
]

现有custom_sso_security_manager.py代码

import logging
from superset.security import SupersetSecurityManager

class CustomSsoSecurityManager(SupersetSecurityManager):

    def oauth_user_info(self, provider, response=None):
        logging.debug("Oauth2 provider: {0}.".format(provider))
        if provider == 'google':
            # As example, this line request a GET to base_url + '/' + userDetails with Bearer  Authentication,
            # and expects that authorization server checks the token, and response with user details
            me = self.appbuilder.sm.oauth_remotes[provider].get('userDetails').data
            logging.debug("user_data: {0}".format(me))
            return { 'name' : me['name'], 'email' : me['email'], 'id' : me['user_name'], 'username' : me['user_name'], 'first_name':'', 'last_name':''}

谷歌云控制台配置重定向URL时,尝试过https://<superset-webserver>/oauth-authorized/google和http://localhost:8088/superset/welcome,均未解决问题。


问题排查与修正方案

1. 重定向URL配置错误

Superset OAuth的正确重定向URL格式为http://<your-superset-host>:<port>/oauth-authorized/<provider-name>,针对本地HTTP服务,应配置为http://localhost:8088/oauth-authorized/google。

在谷歌云控制台的OAuth 2.0客户端ID设置中,确保仅保留此正确的重定向URL,删除其他无效的URL(如/superset/welcome)。

2. 多余的Basic Auth头与重复参数

Google OAuth获取access_token时,不需要额外的Authorization: Basic XXXX头,且remote_app中已配置client_id,无需在access_token_params中重复填写。

修改superset_config.py中的remote_app部分,删除冗余配置:

'remote_app': {
    'client_id':'clientIdfromCredintials',
    'client_secret':'clientsecretfromCredintials',
    'client_kwargs':{
        'scope': 'email profile'
    },
    'access_token_method':'POST',
    'api_base_url':'https://www.googleapis.com/oauth2/v2/',
    'access_token_url':'https://accounts.google.com/o/oauth2/token',
    'authorize_url':'https://accounts.google.com/o/oauth2/auth'
},

3. 用户信息API端点错误

Google OAuth的用户信息端点是userinfo而非userDetails,且返回字段中没有user_name,应使用id或email作为用户标识。

修改custom_sso_security_manager.py的oauth_user_info方法:

import logging
from superset.security import SupersetSecurityManager

class CustomSsoSecurityManager(SupersetSecurityManager):

    def oauth_user_info(self, provider, response=None):
        logging.debug("Oauth2 provider: {0}.".format(provider))
        if provider == 'google':
            me = self.appbuilder.sm.oauth_remotes[provider].get('userinfo').data
            logging.debug("user_data: {0}".format(me))
            # 从返回的用户信息中提取正确字段,谷歌返回的字段包括name、email、id等
            return { 
                'name': me['name'], 
                'email': me['email'], 
                'id': me['id'], 
                'username': me['email'],  # 用邮箱作为用户名
                'first_name': me.get('given_name', ''),
                'last_name': me.get('family_name', '')
            }

4. 确保Docker容器加载自定义配置

如果是通过Docker部署,需确保superset_config.py和custom_sso_security_manager.py已挂载到容器的正确路径(通常是/app/pythonpath/superset_config.py),并重启Superset容器使配置生效。


内容的提问来源于stack exchange,提问作者AB21

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 22:53:09