Manglam44 opened a new issue, #42754:
URL: https://github.com/apache/superset/issues/42754

   ### Bug description
   
   ### Summary
   
   We're trying to embed a Superset dashboard into our own web application 
using the
   Embedded SDK + guest token flow, but have run into multiple errors along the 
way and
   would appreciate a working step-by-step reference from the community, since 
the
   existing docs leave gaps for our setup.
   
   ### What we're trying to achieve
   
   - Embed a single dashboard (view-only) inside our own internal/client-facing 
app
   - No Superset login required for the end user — authenticated via guest token
   - Hide all edit/admin UI (Edit dashboard, chart edit menu, etc.)
   - Restrict embedding to specific approved domains only
   
   ### Steps we've followed so far
   
   1. Enabled `EMBEDDED_SUPERSET` feature flag in `superset_config.py`
   2. Generated an Embedded Dashboard UUID via dashboard "..." → Embed dashboard
   3. Set up a backend service account to call `/api/v1/security/login` then
      `/api/v1/security/guest_token/`
   4. Installed `@superset-ui/embedded-sdk` on the frontend and called 
`embedDashboard(...)`
      with `fetchGuestToken` pointing at our backend endpoint
   
   ### Errors encountered
   
   - <e.g. "Access denied" when loading `?standalone=2` directly>
   - <e.g. "This endpoint requires the datasource X, database or 
all_datasource_access permission">
   - <e.g. CORS error when frontend calls guest_token endpoint>
   - <e.g. iframe stays blank / fails silently with no console error>
   
   ### What we've already tried
   
   - Verified `EMBEDDED_SUPERSET` flag is set and Superset restarted
   - Granted `all_datasource_access` and dashboard-level role access
   - Confirmed the guest token is being generated (valid JWT, correct 
`resources` scope)
   - Tried both with and without `standalone=2` in the URL
   
   ### Question
   
   Could someone share a confirmed-working, current step-by-step flow (or point 
to an
   up-to-date example repo) for:
   
   1. Correct `superset_config.py` settings required for embedding (feature 
flag, CORS,
      GUEST_TOKEN settings, TALISMAN/CSP if relevant)
   2. The exact guest token payload structure expected for the current version
   3. Correct frontend SDK usage/version compatibility
   4. Common causes of "Access denied" / blank iframe when everything above 
appears
      correctly configured
   
   **Happy to share our full config and error logs in the thread. Thanks in 
advance —
   this seems like a common ask so a clear answer here would likely help others 
too.**
   
   ### Screenshots/recordings
   
   _No response_
   
   ### Superset version
   
   master / latest-dev
   
   ### Python version
   
   3.11
   
   ### Node version
   
   16
   
   ### Browser
   
   Chrome
   
   ### Additional context
   
   _No response_
   
   ### Checklist
   
   - [x] I have searched Superset docs and Slack and didn't find a solution to 
my problem.
   - [x] I have searched the GitHub issue tracker and didn't find a similar bug 
report.
   - [x] I have checked Superset's logs for errors and if I found a relevant 
Python stacktrace, I included it here as text in the "additional context" 
section.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to