You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于JEE的pac4j SP对接Hana IDP后,后端认证及数据提取咨询

问题背景

我们已基于JEE示例应用完成与Hana IDP的对接,通过配置Hana IDP所需信息实现了认证流程。

产品架构
  • 前端采用JEE技术栈,后端核心由Java及C++实现;
  • JEE层通过请求用户凭证或可信认证方式,向后端申请企业会话;后端验证通过后,为用户签发有效企业会话。

我们认为基于JEE的pac4j实现及SAML协议适配现有架构,但目前面临两个核心问题:

  1. IDP与SP完成用户认证后,如何在后端对用户进行认证以获取有效企业会话?
  2. 能否从pac4j SP中提取断言等相关数据,传递至后端进行进一步验证?
参考代码
public Config build(final Object... parameters) {

......

final SAML2Configuration cfg = new SAML2Configuration("resource:samlKeystore.jks",
                                            "Password1",
                                            "Password1",
                                            "resource:samltest-providers.xml");
                                            
......

cfg.setMaximumAuthenticationLifetime(3600);
cfg.setServiceProviderEntityId("http://xx.xx.xx.xx:8080/callback?client_name=SAML2Client");
        
cfg.setServiceProviderMetadataPath(new File("sp-metadata.xml").getAbsolutePath());
final SAML2Client saml2Client = new SAML2Client(cfg);

......

final Clients clients = new Clients("http://xx.xx.xx.xx:8080/callback", oidcClient, saml2Client, facebookClient,
        twitterClient, formClient, indirectBasicAuthClient, casClient, stravaClient, parameterClient,
        directBasicAuthClient, new AnonymousClient(), casProxy);
        
final Config config = new Config(clients);
config.addAuthorizer("admin", new RequireAnyRoleAuthorizer("ROLE_ADMIN"));
config.addAuthorizer("custom", new CustomAuthorizer());

.....

final DefaultSessionLogoutHandler defaultCasLogoutHandler = new DefaultSessionLogoutHandler();
defaultCasLogoutHandler.setDestroySession(true);
config.setSessionLogoutHandler(defaultCasLogoutHandler);

return config;
}

解决方案建议

问题1:后端获取有效企业会话的认证方案

IDP与SP完成认证后,JEE层已持有pac4j生成的用户认证信息,可通过以下两种方式对接后端:

  1. 传递可信身份令牌:
    • 用ProfileManager获取已认证的SAML2Profile,提取用户唯一标识(如getNameID())、属性等核心信息;
    • 将这些信息封装为后端认可的可信令牌(如JWT、自定义加密令牌),签名后发送至后端认证接口;
    • 后端验证令牌签名有效性、用户信息合法性后,签发企业会话。
  2. 共享认证上下文:
    • 若后端Java模块可访问共享会话存储(如Redis、数据库),可让后端直接读取pac4j存储的已认证用户Profile;
    • 后端确认认证上下文合法后,直接生成企业会话。

问题2:提取SAML断言并传递至后端

pac4j支持直接提取SAML断言及相关数据,具体操作如下:

  1. 提取断言与属性:
    • 从SAML2Profile调用getSamlAssertion()方法,获取原始SAML断言XML字符串;
    • 通过getAttributes()获取断言中的用户属性集合,按需提取角色、邮箱等字段。
  2. 传递至后端验证:
    • 若后端需要完整断言,可将断言字符串加密后通过HTTP请求体传递;
    • 若仅需核心属性,可封装为JSON等结构化数据,签名后发送;
    • 后端用SAML库(如OpenSAML)验证断言的签名、有效期、受众等字段,合法后完成后续流程。

代码示例补充

在JEE的回调或受保护资源中,可添加如下代码提取并处理认证信息:

// 获取当前认证的用户Profile
ProfileManager profileManager = new ProfileManager<>(request, response);
Optional<SAML2Profile> samlProfile = profileManager.getProfile(SAML2Profile.class);

if (samlProfile.isPresent()) {
    SAML2Profile profile = samlProfile.get();
    // 提取用户唯一标识
    String nameId = profile.getNameID();
    // 提取原始SAML断言
    String samlAssertion = profile.getSamlAssertion();
    // 提取用户属性
    Map<String, Object> attributes = profile.getAttributes();
    
    // 封装数据发送至后端
    // ... 此处编写调用后端认证接口的逻辑
}

内容的提问来源于stack exchange,提问作者user25326988

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 10:57:20