Ubuntu16.04源码安装CKAN2.7.3后Datapusher上传报403错误求助
Hey there, let's work through this 403 Forbidden error you're hitting when trying to use Datapusher. I've debugged this exact issue a handful of times with CKAN 2.x setups, so here are the most common fixes to try step by step:
1. Verify Datapusher API Token & Permissions
First, double-check the API token linking CKAN and Datapusher:
- Generate a valid token for an admin-level CKAN user using the CLI:
paster --plugin=ckan user token add <your-admin-username> datapusher -c /etc/ckan/default/production.ini - Open your CKAN production config (
/etc/ckan/default/production.ini) and make sureckan.datapusher.api_tokenis set to the token you just generated. No extra spaces or typos here—they're easy to miss! - Ensure the user associated with the token has full permissions (admin access is safest for Datapusher, since it needs to modify datasets and push data to the Datastore).
2. Check Datapusher Configuration
Head over to your Datapusher settings file (usually datapusher_settings.py) and confirm these values:
CKAN_API_URL: Must point to your CKAN instance's valid API endpoint, e.g.,http://your-ckan-domain/api/3/action/orhttp://localhost:5000/api/3/action/(if running locally).CKAN_API_KEY: This must match theckan.datapusher.api_tokenin your CKAN config exactly. Even a single character difference will cause a 403.
3. Fix CORS Restrictions
If Datapusher is running on a different port or domain than CKAN, cross-origin requests might be blocked:
- In your CKAN
production.ini, setckan.cors.origin_allow_all = true(for testing) or add Datapusher's full URL to the whitelist:
(Replaceckan.cors.origin_whitelist = http://localhost:8800http://localhost:8800with your Datapusher's actual address.) - Restart CKAN after making this change.
4. Check Service Status & Logs
Let's make sure Datapusher is running and see what's going on under the hood:
- Verify Datapusher is active:
If it's not running, start it withsudo service datapusher statussudo service datapusher start. - Check Datapusher's logs (typically at
/var/log/ckan/datapusher.log) for detailed error messages. Look for lines mentioning "invalid token" or "failed to reach CKAN API"—these will point you directly to the problem. - You can also test the CKAN API directly from the Datapusher server to rule out network issues:
If this returns a JSON list of datasets, your token and network are working.curl -H "Authorization: <your-api-token>" http://your-ckan-api-url/api/3/action/package_list
5. Confirm CKAN User Permissions
Make sure the user trying to upload resources has the right permissions:
- If it's a logged-in user, ensure they're the owner of the dataset or have
update_datasetpermissions. - If you're testing with anonymous users, check that
ckan.auth.anon_create_datasetis set totruein your CKAN config (though this isn't recommended for production).
6. Restart All Relevant Services
After making any configuration changes, don't forget to restart the services to apply them:
sudo service apache2 restart # If using Apache as reverse proxy sudo service ckan restart sudo service datapusher restart
Go through these steps one by one, and you should have that Datapusher working in no time!
内容的提问来源于stack exchange,提问作者Lae

