You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAML 2.0框架迁移后/saml/logout返回404,单点登出失败求助

排查SAML2单点登出404错误的原因及解决方案

1. 端点请求方法不匹配

Spring Security SAML2的logoutUrl("/saml/logout")默认只接受POST请求,如果你发起的是GET请求访问该地址,就会直接返回404。

  • 若要支持GET请求,需显式配置请求匹配器:
.saml2Logout(logout -> logout
        .logoutUrl("/saml/logout")
        .logoutRequestMatcher(new AntPathRequestMatcher("/saml/logout", "GET"))
)

2. 授权规则顺序问题

你的授权规则中,/saml/**的放行规则排在/logout/saml2/slo之后,若存在其他更靠前的拦截规则,可能导致/saml/logout被拦截。调整规则顺序,确保通用放行规则优先:

.authorizeHttpRequests((authorize) -> authorize
        .antMatchers("/saml/**").permitAll()
        .antMatchers(HttpMethod.GET,"/logout/saml2/slo").permitAll()
        .anyRequest().authenticated()
)

3. 依赖方注册(RelyingPartyRegistration)配置缺失

自定义的MyRelyingPartyRegistrationRepository中,必须正确配置IDP的单点登出服务信息,否则Spring Security无法找到跳转目标,会导致端点处理异常。检查配置是否包含:

RelyingPartyRegistration.withRegistrationId("your-reg-id")
        .idpEntityId("idp-entity-id")
        .singleLogoutServiceLocation("idp-slo-url") // 对应IDP元数据中的单点登出地址
        .singleLogoutServiceBinding(Saml2MessageBinding.REDIRECT) // 匹配IDP支持的绑定方式
        // 其他必要配置...
        .build();

4. 自定义过滤器干扰

你添加的SamlExtensionUrlForwardingFilter排在DisableEncodeUrlFilter之前,这个自定义过滤器可能会拦截或修改/saml/logout的请求。可以暂时移除该过滤器,测试是否能正常访问端点,排除过滤器冲突的可能。

5. Spring Security版本兼容性

不同版本的Spring Security SAML2模块配置细节有差异,比如Spring Security 6.x对SAML2的配置逻辑有调整。确认你使用的spring-security-saml2-service-provider依赖版本与配置代码匹配,避免因版本不兼容导致端点未正确注册。


内容的提问来源于stack exchange,提问作者Akhil Ranjan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 14:52:46