You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Auth0 SAML IDP发起登录报错:Unsupported response mode: auth0_pq_openid

Auth0 IDP发起登录报错:unsupported_response_mode: auth0_pq_openid

我们通过Terraform搭建了Auth0架构,包含一个常规Web应用和指向SAMLING的SAML连接,需实现IDP发起的登录功能,同时配置了Post Login Action向id_token添加两个声明。

当SAMLING返回响应后,用户创建和Action触发均正常,但随后被重定向至Auth0错误页面,提示错误:

unsupported_response_mode : Unsupported response mode: auth0_pq_openid

我们未找到关于auth0_pq_openid响应模式的有效资料,尝试设置SAML连接的front_channel和back_channel参数也无效。此前手动在另一账号配置相同功能可正常运行,对比Terraform生成资源与手动配置的属性完全一致,推测Terraform创建资源时存在隐藏默认配置导致问题,已尝试重新创建资源,问题依旧。

正常状态定义:用户创建成功、Action触发成功、用户正常登录并重定向。

已尝试的操作

  • 手动创建资源,功能正常
  • 删除并重新创建Terraform资源,问题未解决
  • 对比手动配置与Terraform生成资源的所有属性,完全一致

Terraform脚本

variable "env" { type = string }
variable "potato_default_role" { type = string }
variable "potato_admin_aggregate_id" { type = string }
variable "auth0_terraform_client_id" { type = string }
variable "auth0_terraform_client_secret" { type = string }
variable "auth0_provider_debug_mode" { type = bool }
variable "auth0_tenant_name" { type = string }

variable "aws_account_id" { type = string }
variable "aws_account_region" { type = string }

variable "mlos_idp_connection_name" { type = string }
variable "customers_idp_connection_debug" { type = bool }
variable "customers_idp_certificate_path" { type = string }
variable "customers_idp_metadata_path" { type = string }
variable "customers_idp_signin_url" { type = string }
variable "customers_idp_redirect_uri" { type = string }
variable "customers_idp_allowed_callbacks" { type = list(string) }
variable "customers_idp_allowed_logout_urls" { type = list(string) }

locals {
  customers_idp_allowed_callbacks = concat(var.customers_idp_allowed_callbacks, [var.customers_idp_redirect_uri])
  auth0_domain = "${var.auth0_tenant_name}.us.auth0.com"
  customers_idp_connection_name = "${var.env}-potato"
}

terraform {
  required_version = ">= 1.5.7"

  required_providers {
    # aws = "5.19.0"
    auth0 = {
      source  = "auth0/auth0"
      version = ">= 1.0.0"
    }
  }

  # backend "s3" { }
}

provider "auth0" {
  domain        = local.auth0_domain
  client_id     = var.auth0_terraform_client_id
  client_secret = var.auth0_terraform_client_secret
  debug         = var.auth0_provider_debug_mode
}

resource "auth0_client" "potato_client_mm" {
  name                                = "${var.env}-potato"
  app_type                            = "non_interactive"
  custom_login_page_on                = false
}

resource "auth0_client" "potato_client" {
  name                                = "${var.env}-homestory"
  app_type                            = "regular_web"
  custom_login_page_on                = true
  is_first_party                      = true
  is_token_endpoint_ip_header_trusted = false
  oidc_conformant                     = true
  callbacks                           = local.customers_idp_allowed_callbacks
  allowed_logout_urls                 = var.customers_idp_allowed_logout_urls
}

resource "auth0_connection" "samlp" {
  name     = local.customers_idp_connection_name
  strategy = "samlp"
  show_as_button = true
  options {
    type                = "front_channel"
    debug               = var.customers_idp_connection_debug
    signing_cert        = file(var.customers_idp_certificate_path)
    sign_in_endpoint    = var.customers_idp_signin_url
    disable_sign_out    = true
    set_user_root_attributes = "on_each_login" 
    protocol_binding    = "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
    user_id_attribute   = "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    signature_algorithm = "rsa-sha256"
    digest_algorithm    = "sha256"
    entity_id           = "urn:auth0:${var.auth0_tenant_name}:${local.customers_idp_connection_name}"
    metadata_xml        = file(var.customers_idp_metadata_path)
    sign_saml_request   = true
    fields_map = jsonencode({
      "email": "Email Address",
      "given_name": "FirstName",
      "name": "FirstName",
      "family_name": "LastName",
      "memberNumber": "MemberNumber",
      "phone_number": "PrimaryPhoneNumber",
    })

    idp_initiated {
      client_id              = auth0_client.potato_client.client_id
      client_protocol        = "openid"
      client_authorize_query = "redirect_uri=${urlencode(var.customers_idp_redirect_uri)}"
    }
  }
}

resource "auth0_connection_client" "potato_client_samlp" {
  connection_id = auth0_connection.samlp.id
  client_id     = auth0_client.potato_client.id
}

resource "auth0_resource_server" "potato_profile_api" {
  name        = "POTATO Profile API"
  identifier  = "https://potato.api/profiles"
  signing_alg = "RS256"
  skip_consent_for_verifiable_first_party_clients = true
}

resource "auth0_resource_server_scopes" "potato_profile_api_scopes" {
  resource_server_identifier = auth0_resource_server.potato_profile_api.identifier
  scopes {
    name        = "profile/write"
    description = "Allows for creating a profile"
  }
  scopes {
    name        = "profile/read"
    description = "Allows for reading a profile by email"
  }
}

resource "auth0_client_grant" "potato_profile_api_grant" {
  client_id = auth0_client.potato_client.id
  audience  = auth0_resource_server.potato_profile_api.identifier
  scopes    = ["profile/read", "profile/write"]
}

resource "auth0_resource_server" "potato_webhooks_api" {
  name        = "POTATO Webhooks API"
  identifier  = "https://potato.api/webhooks"
  signing_alg = "RS256"
  skip_consent_for_verifiable_first_party_clients = true
}

resource "auth0_resource_server_scopes" "potato_webhooks_api_scopes" {
  resource_server_identifier = auth0_resource_server.potato_webhooks_api.identifier
  scopes {
    name        = "webhooks/write"
    description = "Write webhook"
  }
  scopes {
    name        = "webhooks/read"
    description = "Read webhook"
  }
}

resource "auth0_client_grant" "potato_webhooks_api_grant" {
  client_id = auth0_client.potato_client_mm.id
  audience  = auth0_resource_server.potato_webhooks_api.identifier
  scopes    = ["webhooks/read", "webhooks/write"]
}

resource "auth0_client_grant" "auth0_managment_api_grant" {
  client_id = auth0_client.potato_client.id
  audience  = "https://${local.auth0_domain}/api/v2/"
  scopes    = ["update:users", "read:users" , "read:user_idp_tokens"]
}

resource "auth0_log_stream" "aws_event_bridge" {
  name   = "AWS EventBridge"
  type   = "eventbridge"
  status = "active"
  sink {
    aws_account_id = var.aws_account_id
    aws_region     = var.aws_account_region
  }
}

data "auth0_client" "potato_client" {
  client_id = auth0_client.potato_client.client_id
}

resource "auth0_action" "post_login_action" {
  name    = "post_login"
  runtime = "node18"
  deploy  = true
  code    = file("./actions/postLogin/index.js")

  supported_triggers {
    id      = "post-login"
    version = "v3"
  }

  secrets {
    name  = "clientId" 
    value = auth0_client.potato_client.client_id
  }

  secrets {
    name  = "auth0Domain" 
    value = local.auth0_domain
  }

  secrets {
    name  = "auth0URL" 
    value = "https://${local.auth0_domain}"
  }

  secrets {
    name  = "clientSecret" 
    value = data.auth0_client.potato_client.client_secret
  }

  secrets {
    name  = "mloRoleConnection" 
    value = var.mlos_idp_connection_name
  }

  secrets {
    name  = "customerRoleConnection" 
    value = local.customers_idp_connection_name
  }

  secrets {
    name  = "defaultRole" 
    value = var.potato_default_role
  }
}

resource "auth0_trigger_action" "post_login_action_binding" {
  trigger   = "post-login"
  action_id = auth0_action.post_login_action.id
}

resource "auth0_action" "client_credentials_action" {
  name    = "client_credentials"
  runtime = "node18"
  deploy  = true
  code    = file("./actions/clientCredentials/index.js")

  supported_triggers {
    id      = "credentials-exchange"
    version = "v2"
  }

  secrets {
    name  = "adminAggregateId" 
    value = var.potato_admin_aggregate_id
  }
}

resource "auth0_trigger_action" "client_credentials_action_binding" {
  trigger   = "credentials-exchange"
  action_id = auth0_action.client_credentials_action.id
}

output "aws_partner_event_source" {
  description = "AWS Partner event source"
  value       = auth0_log_stream.aws_event_bridge.sink[0].aws_partner_event_source
}

内容的提问来源于stack exchange,提问作者Renato Gama

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 10:44:55