如何让Superset仪表盘仅通过Slug访问?禁用ID访问方式
Great question—this is a common concern when exposing public Superset dashboards, since auto-incrementing IDs make it easy for someone to enumerate and access unintended dashboards. Here are a couple of reliable ways to fix this:
1. Reverse Proxy Interception (Recommended, No Superset Code Modifications)
If you're using a reverse proxy like Nginx in front of Superset, you can add a rule to block any requests targeting dashboards via numeric IDs. This is the cleanest approach because it doesn't require touching Superset's codebase, making future upgrades easier.
Add this location block to your Nginx configuration:
server { # Your existing server configuration (listen, server_name, SSL, etc.) # Block requests to dashboard IDs (numeric paths) location ~* /superset/dashboard/\d+ { return 403 Forbidden; # Optional: Redirect to your intended public dashboard instead of blocking # return 302 /superset/dashboard/test; } # Forward all other Superset requests normally location /superset/ { proxy_pass http://your-superset-internal-address:port; # Add standard proxy headers (adjust as needed) proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
This regex rule matches any URL like {baseURL}/superset/dashboard/123 and returns a 403 Forbidden response, while leaving slug-based paths like {baseURL}/superset/dashboard/test untouched.
2. Custom Flask Middleware (Requires Superset Code Changes)
If you don't have a reverse proxy set up, you can add a custom middleware to Superset's Flask app to intercept and block ID-based dashboard requests. Note that this requires modifying Superset's code, so you'll need to maintain this change through future upgrades.
- Open Superset's main app file (usually
superset/app.py) - Add this middleware class and register it with the Flask app:
from flask import abort from werkzeug.wrappers import Request class BlockDashboardIDMiddleware: def __init__(self, app): self.app = app def __call__(self, environ, start_response): request = Request(environ) # Check if the path is a dashboard ID request if request.path.startswith("/superset/dashboard/"): path_parts = request.path.split("/") # The ID would be the 4th part of the path (e.g., /superset/dashboard/123 → parts[3] = "123") if len(path_parts) >= 4 and path_parts[3].isdigit(): # Optional: Allow internal IPs to use ID paths for admin purposes # client_ip = environ.get("REMOTE_ADDR") # if client_ip not in ["127.0.0.1", "your-internal-admin-ip"]: abort(403) return self.app(environ, start_response) # Register the middleware after creating the Superset app app = create_app() app.wsgi_app = BlockDashboardIDMiddleware(app.wsgi_app)
- Restart your Superset instance for the changes to take effect.
3. Permission System Tweak (Less Direct)
While Superset's permission model ties both slug and ID access to the same can_read permission for a dashboard, you could create a custom role that only allows access to specific dashboards via their slugs. However, this is less reliable because determined users could still find workarounds. The reverse proxy or middleware approaches are far more robust.
内容的提问来源于stack exchange,提问作者Tiago

