You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAML认证异常:Azure AD显示已认证,Firebase返回凭证错误

问题描述

我的应用通过Firebase实现SAML认证,底层用户信息存储在Azure AD,同时使用AWS Cognito提供SAML服务(因为应用最终部署在AWS)。以下是index.js中配置SAML登录的代码:

// SAML Authentication Attempt

//Setting session persistence
setPersistence(auth, browserSessionPersistence)
  .then(() => {
    console.log("Session persistence set to browserSessionPersistence");
  })
  .catch((error) => {
    // Handle Errors here.
    console.error("Error setting persistence", error);
    // Fallback to inMemoryPersistence if browserSessionPersistence fails
    setPersistence(auth, inMemoryPersistence)
      .then(() => {
        console.log("Fallback to inMemoryPersistence");
      })
      .catch((error) => {
        console.error("Error setting inMemory Persistence", error)
      })
  })


// SAML
function ssoSignIn() {
  const provider = new SAMLAuthProvider('saml.saml-aws-iam');
  signInWithRedirect(auth, provider)
    .catch((error) => {
      console.error("Error during signInWithRedirect:", error)
    })
 };

document.getElementById("ssoButton").addEventListener("click", (event) => {
  event.preventDefault(); //Prevent Form Submission
  ssoSignIn();
});


// Loading DOM before attaching event listener
document.addEventListener('DOMContentLoaded', () => {
  const ssoButton = document.getElementById("ssoButton");
  if (ssoButton) {
    ssoButton.addEventListener('click', (event) => {
      event.preventDefault();
      ssoSignIn();
    })
  } else {
    console.error("ssoButton not found in the DOM");
  }

  // Check for redirect result after redirecting back from the SAML Provider
  getRedirectResult(auth)
    .then((result) => {
      if (result && result.user) {
        console.log("User signed in with SSO:", result.user);
        // Redirect
        window.location.href = "dashboard.html";
      } else {
        console.log("No user found after redirect. Result:", result);
      }
    })
    .catch((error) => {
      console.error("Error during getRedirectResult:", error);
    })

})

onAuthStateChanged(auth, (user) => {
  if (user) {
    console.log("User is signed in:", user);
    window.location.href = "dashboard.html";
  } else {
    console.log("No user is signed in.")
  }
})

按代码逻辑,用户登录后应该跳转到dashboard.html或在控制台输出用户信息,但实际出现以下错误:

[Error] Error during getRedirectResult: – FirebaseError: Firebase: All <AudienceRestriction>s should contain the SAML RP entity ID: ' urn:amazon:cognito:sp:[MY-USER-POOL-ID]'. (auth/invalid-credential).
FirebaseError: Firebase: All <AudienceRestriction>s should contain the SAML RP entity ID: ' urn:amazon:cognito:sp:eu-west-2_cD0DvWqD2'. (auth/invalid-credential).
    (anonymous function) (index.js:126)

所有重定向流程正常,Azure AD用户日志显示用户已登录,但Firebase无法返回用户凭证,求助解决办法。

解决方案

这个错误的核心是SAML响应中的<AudienceRestriction>字段未包含Firebase期望的AWS Cognito服务提供商(SP)实体ID,按以下步骤排查修复:

  • 修正Azure AD的SAML声明配置
    登录Azure门户,找到对应SAML企业应用,进入「单一登录」>「用户属性与声明」,确保Audience声明值包含报错中的urn:amazon:cognito:sp:eu-west-2_cD0DvWqD2,注意去掉ID开头的多余空格(报错里的ID前有空格,大概率是配置时误加)。

  • 验证Firebase的SAML提供商设置
    登录Firebase控制台,进入「Authentication」>「Sign-in method」>找到对应的saml.saml-aws-iam提供商,确认「实体ID」字段填写的是正确的Cognito SP实体ID,无拼写错误或多余空格。

  • 检查Cognito与Azure AD的信任关系
    在AWS Cognito用户池的「SAML身份提供商」配置中,确认元数据URL或手动输入的SAML属性正确指向Azure AD元数据,且Cognito的「受众」设置与Azure AD发送的<AudienceRestriction>值完全一致。

  • 清理缓存重测
    清除浏览器缓存和Cookie,避免旧的SAML响应残留导致验证失败,重新发起登录流程测试。

另外,代码中两次绑定了ssoButton的点击事件,虽然不影响功能,但可以合并为一次,减少冗余。

内容的提问来源于stack exchange,提问作者Sushant Agarwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 05:01:03