You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot集成Okta SAML2.0登录AudienceRestriction验证失败排查

Spring Boot集成Okta SAML2.0登录受众验证失败问题排查请求

我基于Spring Boot开发了集成Okta IDP的SAML2.0登录应用,在Okta端完成登录后,页面跳转至应用时出现错误页面http://localhost:8080/login?error。后台日志提示断言中的AudienceRestriction验证失败,具体错误为:断言中的受众与有效受众列表不匹配。以下是相关配置、代码及日志信息,请求排查受众URI错误的原因:

错误信息

Invalid assertion [id19996480044761791773801931] for SAML response [id19996480042980701198640159]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id19996480044761791773801931' was not valid.: None of the audiences within Assertion 'id19996480044761791773801931' matched the list of valid audiances

application.yml配置

spring:
  security:
    saml2:
      relyingparty:
        registration:
          okta-saml:
            assertingparty:
              entity-id: http://www.okta.com/exkar5e4vbGQS6kYS697
              verification.credentials:
                - certificate-location: "classpath:saml-certificate/okta.cert"
              singlesignon.url: https://trial-6443640.okta.com/app/trial-6443640_appsaml1_1/exkar5e4vbGQS6kYS697/sso/saml
              singlesignon.sign-request: false
              audience: http://localhost:8080/login/saml2/service-provider-metadata/okta-saml
              
logging:
  file: logs/application-debug.log
  pattern:
    console: "%d %-5level %logger : %msg%n"
    file: "%d %-5level [%thread] %logger : %msg%n"
  level:
    org.springframework.web: DEBUG
    org.springframework.security: TRACE
    
    server:
  port : 8080

SecurityConfiguration类代码

@Configuration
public class SecurityConfiguration extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity httpSecurity) throws Exception {
      // This class is deprecated, but you have to use it if you're using OpenSAML < 4.0
      OpenSamlAuthenticationProvider authenticationProvider = new OpenSamlAuthenticationProvider();
      authenticationProvider.setAssertionValidator(OpenSamlAuthenticationProvider.createDefaultAssertionValidator());
      authenticationProvider.setResponseAuthenticationConverter(OpenSamlAuthenticationProvider.createDefaultResponseAuthenticationConverter());

      /*httpSecurity.authorizeRequests(authz -> authz.antMatchers("/login/saml2/sso/*").permitAll()
              .antMatchers("/login/saml2/service-provider-metadata/*").permitAll()
                .anyRequest().authenticated())*/
      httpSecurity.authorizeRequests(authz -> authz.anyRequest().authenticated())
        .saml2Login(saml2 -> saml2.authenticationManager(new ProviderManager(authenticationProvider)));
    }

    private Converter<OpenSamlAuthenticationProvider.ResponseToken, Saml2Authentication> groupsConverter() {

        Converter<org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.ResponseToken, Saml2Authentication> delegate =
                OpenSamlAuthenticationProvider.createDefaultResponseAuthenticationConverter();

        return (responseToken) -> {
            Saml2Authentication authentication = delegate.convert(responseToken);
            Saml2AuthenticatedPrincipal principal = (Saml2AuthenticatedPrincipal) authentication.getPrincipal();
            List<String> groups = principal.getAttribute("groups");
            Set<GrantedAuthority> authorities = new HashSet<>();
            if (groups != null) {
                groups.stream().map(SimpleGrantedAuthority::new).forEach(authorities::add);
            } else {
                authorities.addAll(authentication.getAuthorities());
            }
            return new Saml2Authentication(principal, authentication.getSaml2Response(), authorities);
        };
    }
}

控制器代码

@SpringBootApplication
@Controller
public class SpringSecuritySaml2Application {

    public static void main(String[] args) {
        SpringApplication.run(SpringSecuritySaml2Application.class, args);
    }
    @RequestMapping("/")
    public String index() {
        return "home";
    }

    @RequestMapping("/secured/hello")
    public String hello(@AuthenticationPrincipal Saml2AuthenticatedPrincipal principal, Model model) {
        model.addAttribute("name", principal.getName());
        return "hello";
    }

}

日志片段

2024-01-24 12:28:35,274 DEBUG org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider : Found 1 validation errors in SAML response [id3210990765450188248512483]: [[invalid_assertion] Invalid assertion [id32109907656084221846235013] for SAML response [id3210990765450188248512483]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id32109907656084221846235013' was not valid.: None of the audiences within Assertion 'id32109907656084221846235013' matched the list of valid audiances]
2024-01-24 12:28:35,275 TRACE org.springframework.security.saml2.provider.service.servlet.filter.Saml2WebSsoAuthenticationFilter : Failed to process authentication request
org.springframework.security.saml2.provider.service.authentication.Saml2AuthenticationException: Invalid assertion [id32109907656084221846235013] for SAML response [id3210990765450188248512483]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id32109907656084221846235013' was not valid.: None of the audiences within Assertion 'id32109907656084221846235013' matched the list of valid audiances
    at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.createAuthenticationException(OpenSamlAuthenticationProvider.java:699)
    at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.process(OpenSamlAuthenticationProvider.java:519)
    at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.authenticate(OpenSamlAuthenticationProvider.java:447)
    at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:182)

Okta配置截图

Okta配置截图


内容的提问来源于stack exchange,提问作者BK Elizabeth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 13:43:15