基于Sustainsys.Saml2的Blazor应用SSO豁免页面配置咨询
Blazor + Sustainsys.Saml2 配置公开访问页面
问题背景
我们基于.NET 6.0和Sustainsys.Saml2 2.9.0构建了Blazor应用,通过SAML 2协议与WSO2服务器实现SSO登录,目前所有页面均受SSO保护。需要将其中一个页面设置为公开访问,无需经过SSO认证,但查阅Sustainsys.Saml2文档及示例未找到明确的页面排除方法,修改Program.cs认证授权代码、调整App.razor认证设置后仍未解决,不确定是否需要通过.NET内置授权策略创建自定义策略替代默认策略。
当前Program.cs代码
builder.Services.AddAuthentication(sharedOptions => { sharedOptions.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; sharedOptions.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; sharedOptions.DefaultChallengeScheme = "Saml2"; }) .AddSaml2(options => { options.SPOptions.EntityId = new EntityId(ApplicationSettings.Environment); options.SPOptions.PublicOrigin = new Uri(ApplicationSettings.Environment, UriKind.RelativeOrAbsolute); options.IdentityProviders.Add( new IdentityProvider( new EntityId(ApplicationSettings.EntityId), options.SPOptions) { MetadataLocation = ApplicationSettings.SamlCertificate }); }) .AddCookie(); builder.Services.AddAuthorization(options => { options.FallbackPolicy = options.DefaultPolicy; });
当前App.razor代码
<CascadingAuthenticationState> <Router AppAssembly="@typeof(App).Assembly"> <Found Context="routeData"> <AuthorizeRouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)"> <Authorizing> <text>Please wait, we are authorizing you...</text> </Authorizing> <NotAuthorized> <text>You are not authorized to access this application. Contact the help desk if you think there is a problem.</text> </NotAuthorized> </AuthorizeRouteView> <FocusOnNavigate RouteData="@routeData" Selector="h1" /> </Found> <NotFound> <PageTitle>Not found</PageTitle> <LayoutView Layout="@typeof(MainLayout)"> <p role="alert">Sorry, there's nothing at this address.</p> </LayoutView> </NotFound> </Router> </CascadingAuthenticationState> @{}
解决方案
1. 调整授权策略配置
问题核心在于你设置了options.FallbackPolicy = options.DefaultPolicy;,而.NET的默认授权策略DefaultPolicy强制要求用户已认证,因此所有未指定授权规则的页面都会触发SSO认证跳转。我们需要保留默认认证策略的同时,添加允许匿名访问的规则:
修改Program.cs中的AddAuthorization代码:
builder.Services.AddAuthorization(options => { // 保留默认策略:要求用户已认证 options.DefaultPolicy = new AuthorizationPolicyBuilder() .RequireAuthenticatedUser() .Build(); // 添加允许匿名访问的自定义策略 options.AddPolicy("AllowAnonymous", policy => policy.AllowAnonymous()); // 若需大部分页面默认认证,少数公开,保持FallbackPolicy为DefaultPolicy即可 // 公开页面将通过特性或路由判断跳过认证 });
2. 给目标公开页面添加匿名访问标记
在需要公开的Blazor页面(例如PublicPage.razor)顶部添加[AllowAnonymous]特性,该特性会覆盖全局的 fallback 认证要求:
@page "/public" @attribute [AllowAnonymous] <h3>公开访问页面</h3> <!-- 页面内容 -->
3. 可选:通过路由判断实现公开访问(无需修改页面)
如果不想给页面添加特性,也可以在App.razor中根据路由直接跳过授权验证:
<CascadingAuthenticationState> <Router AppAssembly="@typeof(App).Assembly"> <Found Context="routeData"> @{ // 定义公开页面的路由,这里以"/public"为例 var isPublicRoute = routeData.RouteValues["page"]?.ToString() == "/public"; } @if (isPublicRoute) { <!-- 公开页面直接渲染,不经过授权验证 --> <RouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)" /> } else { <!-- 其他页面仍走授权流程 --> <AuthorizeRouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)"> <Authorizing> <text>Please wait, we are authorizing you...</text> </Authorizing> <NotAuthorized> <text>You are not authorized to access this application. Contact the help desk if you think there is a problem.</text> </NotAuthorized> </AuthorizeRouteView> } <FocusOnNavigate RouteData="@routeData" Selector="h1" /> </Found> <NotFound> <PageTitle>Not found</PageTitle> <LayoutView Layout="@typeof(MainLayout)"> <p role="alert">Sorry, there's nothing at this address.</p> </LayoutView> </NotFound> </Router> </CascadingAuthenticationState>
4. 注意事项
- Sustainsys.Saml2的默认回调路径(如
/Saml2/Acs、/Saml2/Logout)无需额外配置,组件本身已确保这些路径可正常访问,不会被授权拦截。 - 若后续添加了自定义中间件,需确保这些SAML相关路径不会被中间件拦截。
内容的提问来源于stack exchange,提问作者Matt L
相关产品推荐
相关产品推荐

