ITfoxtec SAML 4.8.8:如何完全忽略AuthnContext验证?
解决ITfoxtec 4.8.8解析SAML2响应时AuthnContext导致的空引用异常
这个问题的根源是微软官方的Saml2Serializer在处理仅包含<saml:AuthnContextDeclRef>的<saml:AuthnContext>节点时,会触发空引用异常。由于响应已加密签名无法修改,你可以通过自定义Saml2序列化器来绕过这个限制,同时不破坏签名验证。
解决方案步骤:
- 自定义继承自
Saml2Serializer的类,重写ReadAuthenticationContext方法,手动处理仅存在AuthnContextDeclRef的场景:
public class CustomSaml2Serializer : Microsoft.IdentityModel.Tokens.Saml2.Saml2Serializer { protected override Saml2AuthenticationContext ReadAuthenticationContext(XmlDictionaryReader reader) { var authContext = new Saml2AuthenticationContext(); reader.ReadStartElement("AuthnContext", Saml2Constants.Namespace); while (reader.IsStartElement()) { if (reader.LocalName == "AuthnContextClassRef" && reader.NamespaceURI == Saml2Constants.Namespace) { authContext.ClassReference = new Uri(reader.ReadElementContentAsString(), UriKind.RelativeOrAbsolute); } else if (reader.LocalName == "AuthnContextDeclRef" && reader.NamespaceURI == Saml2Constants.Namespace) { authContext.DeclarationReference = new Uri(reader.ReadElementContentAsString(), UriKind.RelativeOrAbsolute); // 避免ClassReference为null触发空引用,直接指定默认值 authContext.ClassReference ??= new Uri("urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified"); } else { reader.Skip(); } } reader.ReadEndElement(); return authContext; } }
- 在读取SAML响应时,给绑定指定自定义序列化器:
var genericSamlRequest = Request.ToGenericHttpRequest(); var binding = new Saml2PostBinding(); // 注入自定义序列化器 binding.Saml2Serializer = new CustomSaml2Serializer(); var authResponse = new Saml2AuthnResponse(configuration); binding.ReadSamlResponse(genericSamlRequest, authResponse);
这种方式不会修改原始SAML响应内容,因此签名验证可以正常通过,同时解决了空引用异常问题。目前ITfoxtec 4.8.8版本没有直接忽略AuthnContext验证的配置项,自定义序列化器是最可行的方案。
内容的提问来源于stack exchange,提问作者baenziger
相关产品推荐
相关产品推荐

