You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Superset仪表盘仅通过Slug访问?禁用ID访问方式

Solutions to Block Dashboard ID Access in Superset

Great question—this is a common concern when exposing public Superset dashboards, since auto-incrementing IDs make it easy for someone to enumerate and access unintended dashboards. Here are a couple of reliable ways to fix this:

If you're using a reverse proxy like Nginx in front of Superset, you can add a rule to block any requests targeting dashboards via numeric IDs. This is the cleanest approach because it doesn't require touching Superset's codebase, making future upgrades easier.

Add this location block to your Nginx configuration:

server {
    # Your existing server configuration (listen, server_name, SSL, etc.)

    # Block requests to dashboard IDs (numeric paths)
    location ~* /superset/dashboard/\d+ {
        return 403 Forbidden;
        # Optional: Redirect to your intended public dashboard instead of blocking
        # return 302 /superset/dashboard/test;
    }

    # Forward all other Superset requests normally
    location /superset/ {
        proxy_pass http://your-superset-internal-address:port;
        # Add standard proxy headers (adjust as needed)
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

This regex rule matches any URL like {baseURL}/superset/dashboard/123 and returns a 403 Forbidden response, while leaving slug-based paths like {baseURL}/superset/dashboard/test untouched.

2. Custom Flask Middleware (Requires Superset Code Changes)

If you don't have a reverse proxy set up, you can add a custom middleware to Superset's Flask app to intercept and block ID-based dashboard requests. Note that this requires modifying Superset's code, so you'll need to maintain this change through future upgrades.

  1. Open Superset's main app file (usually superset/app.py)
  2. Add this middleware class and register it with the Flask app:
from flask import abort
from werkzeug.wrappers import Request

class BlockDashboardIDMiddleware:
    def __init__(self, app):
        self.app = app

    def __call__(self, environ, start_response):
        request = Request(environ)
        # Check if the path is a dashboard ID request
        if request.path.startswith("/superset/dashboard/"):
            path_parts = request.path.split("/")
            # The ID would be the 4th part of the path (e.g., /superset/dashboard/123 → parts[3] = "123")
            if len(path_parts) >= 4 and path_parts[3].isdigit():
                # Optional: Allow internal IPs to use ID paths for admin purposes
                # client_ip = environ.get("REMOTE_ADDR")
                # if client_ip not in ["127.0.0.1", "your-internal-admin-ip"]:
                abort(403)
        return self.app(environ, start_response)

# Register the middleware after creating the Superset app
app = create_app()
app.wsgi_app = BlockDashboardIDMiddleware(app.wsgi_app)
  1. Restart your Superset instance for the changes to take effect.

3. Permission System Tweak (Less Direct)

While Superset's permission model ties both slug and ID access to the same can_read permission for a dashboard, you could create a custom role that only allows access to specific dashboards via their slugs. However, this is less reliable because determined users could still find workarounds. The reverse proxy or middleware approaches are far more robust.


内容的提问来源于stack exchange,提问作者Tiago

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 13:38:14