Superset集成Keycloak后实现基于组的仪表盘访问控制及代码修改
Alright, let's walk through how to set up granular dashboard access based on Keycloak groups in your already integrated Superset instance. Most of this work happens in the UI, but I'll also cover scenarios where you might need to tweak code/config.
First: Prep Keycloak Groups (No Code Needed)
Before jumping into Superset, make sure your Keycloak setup is ready:
- Create two groups in Keycloak: say
dashboard-viewers-1-2anddashboard-viewer-3 - Add User 1 to
dashboard-viewers-1-2, and User 3 todashboard-viewer-3 - Double-check that your existing Superset-Keycloak integration is syncing groups (this should be enabled in your OIDC config already, but if not, we'll fix that later)
Core Setup: Superset UI Configuration (No Code Needed)
This is where you'll map Keycloak groups to Superset permissions:
Create Role for Each Dashboard Set
- Head to
Security > Rolesin Superset - Make a new role named
access-dash-1-2:- Go to the
Permissionstab and add thecan read on Dashboardpermission (or use more granular permissions if you want tighter control) - Switch to the
Dashboardstab, find Dashboard 1 and 2, and assign thereadpermission to this role
- Go to the
- Repeat the process for a role
access-dash-3, linking it only to Dashboard 3
- Head to
Link Keycloak Groups to Superset Roles
- Back in
Security > Roles, edit theaccess-dash-1-2role - Go to the
Groupstab, search for the synced Keycloak groupdashboard-viewers-1-2, and add it - Do the same for
access-dash-3and its corresponding Keycloak group
- Back in
Test It Out
- Log in as User 1: you should only see Dashboard 1 and 2
- Log in as User 3: only Dashboard 3 should be visible
When You Need Code/Config Tweaks
If your Keycloak group names don't match what you want in Superset, or if group sync isn't working as expected, here's what to do:
1. Map Keycloak Groups to Superset Groups (Modify superset_config.py)
If you need to rename or filter groups coming from Keycloak, add this to your config:
# Enable group sync on every user login OIDC_GROUPS_SYNC_AT_LOGIN = True # Map Keycloak group names to your preferred Superset group names OIDC_GROUP_MAP = { "keycloak-dash-group-1": "dashboard-viewers-1-2", "keycloak-dash-group-3": "dashboard-viewer-3" }
2. Custom Group Sync Logic (Extend Security Manager)
For more complex scenarios—like filtering groups based on user attributes, or transforming group names dynamically—create a custom security manager:
- Add this to
superset_config.py:
from superset.security import SupersetSecurityManager class CustomOIDCSecurityManager(SupersetSecurityManager): def oauth_user_info(self, provider, response=None): # Pull default user info from the OIDC response user_info = super().oauth_user_info(provider, response) # Extract groups from Keycloak's token payload keycloak_groups = response.get("groups", []) # Example: Filter groups to only those related to dashboards, and strip a prefix processed_groups = [g.replace("kc-", "") for g in keycloak_groups if "dashboard" in g] user_info["groups"] = processed_groups return user_info # Tell Superset to use your custom security manager CUSTOM_SECURITY_MANAGER = CustomOIDCSecurityManager
- Restart your Superset service to apply the changes
Quick Notes
- Always ensure
OIDC_GROUPS_SYNC_AT_LOGINis set toTrueso group updates in Keycloak reflect in Superset on the next user login - If users were logged in before you made changes, have them log out and back in (or manually refresh their group info in
Security > Users) - Test in incognito windows to avoid browser cache messing with your results
内容的提问来源于stack exchange,提问作者kalyan4uonly

