You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在ASP.NET MVC中基于Sustainsys.Saml2实现单点注销(SLO)

在ASP.NET MVC中基于Sustainsys.Saml2.Owin实现Salesforce SAML单点注销(SLO)

你的SSO已正常运行,要实现用户退出应用时同时注销Salesforce会话,需完成以下核心步骤:配置Salesforce IdP端的SLO设置、调整Sustainsys.Saml2的服务提供商(SP)配置、实现应用内注销逻辑。

1. Salesforce端SLO配置

登录Salesforce后台,进入Setup > Apps > App Manager,找到你的SAML应用并点击「Edit」:

  • 在「Single Sign-On Settings」区域,勾选Enable Single Logout
  • 设置「Single Logout URL」为你的应用的SAML注销端点,默认是 https://你的应用域名/Saml2/Logout
  • 「Issuer」填写你的SP EntityId(需和Startup里配置的完全一致)
  • 若需验证SLO响应,上传你的SP签名证书到「Certificate」字段

2. 修改Sustainsys.Saml2的Startup配置

调整CreateSaml2Options方法,添加SP注销配置和签名证书(Salesforce要求SLO请求必须签名):

public class Startup
{
    public void Configuration(IAppBuilder app)
    {
        app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

        app.UseCookieAuthentication(new CookieAuthenticationOptions
        {
            AuthenticationType = "Saml2",
            CookieManager = new Microsoft.Owin.Host.SystemWeb.SystemWebChunkingCookieManager(),
            SlidingExpiration = true,
            ExpireTimeSpan = TimeSpan.FromMinutes(Convert.ToDouble(ConfigurationManager.AppSettings["sessionTime"].ToString()))
        });

        app.UseSaml2Authentication(CreateSaml2Options());
    }

    private Saml2AuthenticationOptions CreateSaml2Options()
    {
        var saml2Options = new Saml2AuthenticationOptions(false)
        {
            SPOptions = new SPOptions
            {
                EntityId = new EntityId(ConfigurationManager.AppSettings["EntityId"].ToString()),
                ReturnUrl = new Uri(ConfigurationManager.AppSettings["ReturnUrl"].ToString()),
                // 配置SP注销后的回调地址(SLO完成后跳转)
                LogoutUrl = new Uri("https://你的应用域名/Account/LogoutCallback"),
                // 配置签名证书,用于签署SLO请求
                SigningCertificate = LoadSigningCertificate()
            },
        };

        var idp = new IdentityProvider(
            new EntityId(ConfigurationManager.AppSettings["IssuerUrl"].ToString()),
            saml2Options.SPOptions)
        {
            LoadMetadata = true,
            SingleSignOnServiceUrl = new Uri(ConfigurationManager.AppSettings["SingleSignOnServiceUrl"].ToString()),
            MetadataLocation = ConfigurationManager.AppSettings["MetadataLocation"].ToString(),
            AllowUnsolicitedAuthnResponse = true,
            // 如果元数据未自动加载Salesforce的SLO地址,可手动指定
            // SingleLogoutServiceUrl = new Uri("https://login.salesforce.com/services/oauth2/saml2/logout")
        };

        saml2Options.IdentityProviders.Add(idp);
        saml2Options.AuthenticationType = "Saml2";
        return saml2Options;
    }

    // 加载签名证书的辅助方法(示例从本地文件加载)
    private X509Certificate2 LoadSigningCertificate()
    {
        var certPath = HostingEnvironment.MapPath("~/App_Data/YourSPCert.pfx");
        return new X509Certificate2(certPath, "你的证书密码");
    }
}

3. 实现应用内的注销控制器逻辑

在AccountController中添加注销动作,先清除本地认证Cookie,再发起SAML SLO请求到Salesforce:

public class AccountController : Controller
{
    public ActionResult Logout()
    {
        // 清除本地SAML认证Cookie
        var authManager = Request.GetOwinContext().Authentication;
        authManager.SignOut("Saml2");

        // 发起SAML单点注销请求,自动跳转到Salesforce注销页面
        return new Saml2LogoutResult();
    }

    // SLO完成后的回调动作,可自定义跳转逻辑
    public ActionResult LogoutCallback()
    {
        return RedirectToAction("Index", "Home");
    }
}

关键注意事项

  • 确保Salesforce的SAML应用配置中的Entity ID和你SP的EntityId完全一致
  • 签名证书必须是Salesforce信任的证书:若使用自签名证书,需将证书公钥导入Salesforce的Setup > Security > Certificate and Key Management
  • 测试时,访问你的应用的/Account/Logout地址,会先清除本地会话,再跳转到Salesforce完成注销,最后返回你的LogoutCallback页面

内容的提问来源于stack exchange,提问作者Shahab khan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 20:17:27