You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Sustainsys.Saml2的Blazor应用SSO豁免页面配置咨询

Blazor + Sustainsys.Saml2 配置公开访问页面

问题背景

我们基于.NET 6.0和Sustainsys.Saml2 2.9.0构建了Blazor应用,通过SAML 2协议与WSO2服务器实现SSO登录,目前所有页面均受SSO保护。需要将其中一个页面设置为公开访问,无需经过SSO认证,但查阅Sustainsys.Saml2文档及示例未找到明确的页面排除方法,修改Program.cs认证授权代码、调整App.razor认证设置后仍未解决,不确定是否需要通过.NET内置授权策略创建自定义策略替代默认策略。

当前Program.cs代码

builder.Services.AddAuthentication(sharedOptions =>
{
    sharedOptions.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    sharedOptions.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    sharedOptions.DefaultChallengeScheme = "Saml2";
})
.AddSaml2(options =>
{
    options.SPOptions.EntityId = new EntityId(ApplicationSettings.Environment);
    options.SPOptions.PublicOrigin = new Uri(ApplicationSettings.Environment, UriKind.RelativeOrAbsolute);
    options.IdentityProviders.Add(
      new IdentityProvider(
        new EntityId(ApplicationSettings.EntityId), options.SPOptions)
      {
          MetadataLocation = ApplicationSettings.SamlCertificate
      });
})
.AddCookie();

builder.Services.AddAuthorization(options =>
{
    options.FallbackPolicy = options.DefaultPolicy;
});

当前App.razor代码

<CascadingAuthenticationState>
    <Router AppAssembly="@typeof(App).Assembly">
        <Found Context="routeData">
            <AuthorizeRouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)">
                <Authorizing>
                    <text>Please wait, we are authorizing you...</text>
                </Authorizing>
                <NotAuthorized>
                    <text>You are not authorized to access this application. Contact the help desk if you think there is a problem.</text>
                   
                </NotAuthorized>
            </AuthorizeRouteView>
            <FocusOnNavigate RouteData="@routeData" Selector="h1" />
        </Found>
        <NotFound>
            <PageTitle>Not found</PageTitle>
            <LayoutView Layout="@typeof(MainLayout)">
                <p role="alert">Sorry, there's nothing at this address.</p>
            </LayoutView>
        </NotFound>
    </Router>
</CascadingAuthenticationState>
@{}

解决方案

1. 调整授权策略配置

问题核心在于你设置了options.FallbackPolicy = options.DefaultPolicy;,而.NET的默认授权策略DefaultPolicy强制要求用户已认证,因此所有未指定授权规则的页面都会触发SSO认证跳转。我们需要保留默认认证策略的同时,添加允许匿名访问的规则:

修改Program.cs中的AddAuthorization代码:

builder.Services.AddAuthorization(options =>
{
    // 保留默认策略:要求用户已认证
    options.DefaultPolicy = new AuthorizationPolicyBuilder()
        .RequireAuthenticatedUser()
        .Build();

    // 添加允许匿名访问的自定义策略
    options.AddPolicy("AllowAnonymous", policy =>
        policy.AllowAnonymous());

    // 若需大部分页面默认认证,少数公开,保持FallbackPolicy为DefaultPolicy即可
    // 公开页面将通过特性或路由判断跳过认证
});

2. 给目标公开页面添加匿名访问标记

在需要公开的Blazor页面(例如PublicPage.razor)顶部添加[AllowAnonymous]特性,该特性会覆盖全局的 fallback 认证要求:

@page "/public"
@attribute [AllowAnonymous]

<h3>公开访问页面</h3>
<!-- 页面内容 -->

3. 可选:通过路由判断实现公开访问(无需修改页面)

如果不想给页面添加特性,也可以在App.razor中根据路由直接跳过授权验证:

<CascadingAuthenticationState>
    <Router AppAssembly="@typeof(App).Assembly">
        <Found Context="routeData">
            @{
                // 定义公开页面的路由,这里以"/public"为例
                var isPublicRoute = routeData.RouteValues["page"]?.ToString() == "/public";
            }
            @if (isPublicRoute)
            {
                <!-- 公开页面直接渲染,不经过授权验证 -->
                <RouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)" />
            }
            else
            {
                <!-- 其他页面仍走授权流程 -->
                <AuthorizeRouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)">
                    <Authorizing>
                        <text>Please wait, we are authorizing you...</text>
                    </Authorizing>
                    <NotAuthorized>
                        <text>You are not authorized to access this application. Contact the help desk if you think there is a problem.</text>
                    </NotAuthorized>
                </AuthorizeRouteView>
            }
            <FocusOnNavigate RouteData="@routeData" Selector="h1" />
        </Found>
        <NotFound>
            <PageTitle>Not found</PageTitle>
            <LayoutView Layout="@typeof(MainLayout)">
                <p role="alert">Sorry, there's nothing at this address.</p>
            </LayoutView>
        </NotFound>
    </Router>
</CascadingAuthenticationState>

4. 注意事项

  • Sustainsys.Saml2的默认回调路径(如/Saml2/Acs、/Saml2/Logout)无需额外配置,组件本身已确保这些路径可正常访问,不会被授权拦截。
  • 若后续添加了自定义中间件,需确保这些SAML相关路径不会被中间件拦截。

内容的提问来源于stack exchange,提问作者Matt L

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 22:53:16