Auth0 SAML IDP发起登录报错:Unsupported response mode: auth0_pq_openid
Auth0 IDP发起登录报错:unsupported_response_mode: auth0_pq_openid
我们通过Terraform搭建了Auth0架构,包含一个常规Web应用和指向SAMLING的SAML连接,需实现IDP发起的登录功能,同时配置了Post Login Action向id_token添加两个声明。
当SAMLING返回响应后,用户创建和Action触发均正常,但随后被重定向至Auth0错误页面,提示错误:
unsupported_response_mode : Unsupported response mode: auth0_pq_openid
我们未找到关于auth0_pq_openid响应模式的有效资料,尝试设置SAML连接的front_channel和back_channel参数也无效。此前手动在另一账号配置相同功能可正常运行,对比Terraform生成资源与手动配置的属性完全一致,推测Terraform创建资源时存在隐藏默认配置导致问题,已尝试重新创建资源,问题依旧。
正常状态定义:用户创建成功、Action触发成功、用户正常登录并重定向。
已尝试的操作
- 手动创建资源,功能正常
- 删除并重新创建Terraform资源,问题未解决
- 对比手动配置与Terraform生成资源的所有属性,完全一致
Terraform脚本
variable "env" { type = string } variable "potato_default_role" { type = string } variable "potato_admin_aggregate_id" { type = string } variable "auth0_terraform_client_id" { type = string } variable "auth0_terraform_client_secret" { type = string } variable "auth0_provider_debug_mode" { type = bool } variable "auth0_tenant_name" { type = string } variable "aws_account_id" { type = string } variable "aws_account_region" { type = string } variable "mlos_idp_connection_name" { type = string } variable "customers_idp_connection_debug" { type = bool } variable "customers_idp_certificate_path" { type = string } variable "customers_idp_metadata_path" { type = string } variable "customers_idp_signin_url" { type = string } variable "customers_idp_redirect_uri" { type = string } variable "customers_idp_allowed_callbacks" { type = list(string) } variable "customers_idp_allowed_logout_urls" { type = list(string) } locals { customers_idp_allowed_callbacks = concat(var.customers_idp_allowed_callbacks, [var.customers_idp_redirect_uri]) auth0_domain = "${var.auth0_tenant_name}.us.auth0.com" customers_idp_connection_name = "${var.env}-potato" } terraform { required_version = ">= 1.5.7" required_providers { # aws = "5.19.0" auth0 = { source = "auth0/auth0" version = ">= 1.0.0" } } # backend "s3" { } } provider "auth0" { domain = local.auth0_domain client_id = var.auth0_terraform_client_id client_secret = var.auth0_terraform_client_secret debug = var.auth0_provider_debug_mode } resource "auth0_client" "potato_client_mm" { name = "${var.env}-potato" app_type = "non_interactive" custom_login_page_on = false } resource "auth0_client" "potato_client" { name = "${var.env}-homestory" app_type = "regular_web" custom_login_page_on = true is_first_party = true is_token_endpoint_ip_header_trusted = false oidc_conformant = true callbacks = local.customers_idp_allowed_callbacks allowed_logout_urls = var.customers_idp_allowed_logout_urls } resource "auth0_connection" "samlp" { name = local.customers_idp_connection_name strategy = "samlp" show_as_button = true options { type = "front_channel" debug = var.customers_idp_connection_debug signing_cert = file(var.customers_idp_certificate_path) sign_in_endpoint = var.customers_idp_signin_url disable_sign_out = true set_user_root_attributes = "on_each_login" protocol_binding = "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" user_id_attribute = "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" signature_algorithm = "rsa-sha256" digest_algorithm = "sha256" entity_id = "urn:auth0:${var.auth0_tenant_name}:${local.customers_idp_connection_name}" metadata_xml = file(var.customers_idp_metadata_path) sign_saml_request = true fields_map = jsonencode({ "email": "Email Address", "given_name": "FirstName", "name": "FirstName", "family_name": "LastName", "memberNumber": "MemberNumber", "phone_number": "PrimaryPhoneNumber", }) idp_initiated { client_id = auth0_client.potato_client.client_id client_protocol = "openid" client_authorize_query = "redirect_uri=${urlencode(var.customers_idp_redirect_uri)}" } } } resource "auth0_connection_client" "potato_client_samlp" { connection_id = auth0_connection.samlp.id client_id = auth0_client.potato_client.id } resource "auth0_resource_server" "potato_profile_api" { name = "POTATO Profile API" identifier = "https://potato.api/profiles" signing_alg = "RS256" skip_consent_for_verifiable_first_party_clients = true } resource "auth0_resource_server_scopes" "potato_profile_api_scopes" { resource_server_identifier = auth0_resource_server.potato_profile_api.identifier scopes { name = "profile/write" description = "Allows for creating a profile" } scopes { name = "profile/read" description = "Allows for reading a profile by email" } } resource "auth0_client_grant" "potato_profile_api_grant" { client_id = auth0_client.potato_client.id audience = auth0_resource_server.potato_profile_api.identifier scopes = ["profile/read", "profile/write"] } resource "auth0_resource_server" "potato_webhooks_api" { name = "POTATO Webhooks API" identifier = "https://potato.api/webhooks" signing_alg = "RS256" skip_consent_for_verifiable_first_party_clients = true } resource "auth0_resource_server_scopes" "potato_webhooks_api_scopes" { resource_server_identifier = auth0_resource_server.potato_webhooks_api.identifier scopes { name = "webhooks/write" description = "Write webhook" } scopes { name = "webhooks/read" description = "Read webhook" } } resource "auth0_client_grant" "potato_webhooks_api_grant" { client_id = auth0_client.potato_client_mm.id audience = auth0_resource_server.potato_webhooks_api.identifier scopes = ["webhooks/read", "webhooks/write"] } resource "auth0_client_grant" "auth0_managment_api_grant" { client_id = auth0_client.potato_client.id audience = "https://${local.auth0_domain}/api/v2/" scopes = ["update:users", "read:users" , "read:user_idp_tokens"] } resource "auth0_log_stream" "aws_event_bridge" { name = "AWS EventBridge" type = "eventbridge" status = "active" sink { aws_account_id = var.aws_account_id aws_region = var.aws_account_region } } data "auth0_client" "potato_client" { client_id = auth0_client.potato_client.client_id } resource "auth0_action" "post_login_action" { name = "post_login" runtime = "node18" deploy = true code = file("./actions/postLogin/index.js") supported_triggers { id = "post-login" version = "v3" } secrets { name = "clientId" value = auth0_client.potato_client.client_id } secrets { name = "auth0Domain" value = local.auth0_domain } secrets { name = "auth0URL" value = "https://${local.auth0_domain}" } secrets { name = "clientSecret" value = data.auth0_client.potato_client.client_secret } secrets { name = "mloRoleConnection" value = var.mlos_idp_connection_name } secrets { name = "customerRoleConnection" value = local.customers_idp_connection_name } secrets { name = "defaultRole" value = var.potato_default_role } } resource "auth0_trigger_action" "post_login_action_binding" { trigger = "post-login" action_id = auth0_action.post_login_action.id } resource "auth0_action" "client_credentials_action" { name = "client_credentials" runtime = "node18" deploy = true code = file("./actions/clientCredentials/index.js") supported_triggers { id = "credentials-exchange" version = "v2" } secrets { name = "adminAggregateId" value = var.potato_admin_aggregate_id } } resource "auth0_trigger_action" "client_credentials_action_binding" { trigger = "credentials-exchange" action_id = auth0_action.client_credentials_action.id } output "aws_partner_event_source" { description = "AWS Partner event source" value = auth0_log_stream.aws_event_bridge.sink[0].aws_partner_event_source }
内容的提问来源于stack exchange,提问作者Renato Gama
相关产品推荐
相关产品推荐

