从spring-security-saml2-core升级至Spring Security SAML2 Service Provider:SAMLEntryPoint等效类及SP发起SSO流程咨询
SAMLEntryPoint in Spring Security SAML2 Service Provider & SP-Initiated SSO Steps Great question! Moving from the legacy spring-security-saml2-core (now EOL) to Spring Security's native SAML2 SP support is a common upgrade, and it’s totally normal to look for equivalents to familiar components like SAMLEntryPoint. Let’s break this down clearly:
1. Equivalent to SAMLEntryPoint
The old SAMLEntryPoint existed to trigger SP-initiated SSO by redirecting users to the Identity Provider (Okta, in your case). In Spring Security’s built-in SAML2 support, there’s no 1:1 class replacement, but the core functionality is covered by two key components:
- Saml2AuthenticationRequestRedirectFilter
This filter is automatically registered when you configure saml2Login() in your security filter chain. It handles requests to the default SSO initiation path (typically /saml2/authenticate/{registrationId}) and redirects users to the IDP’s SSO endpoint with a valid SAML AuthnRequest.
- Saml2AuthenticationRequestResolver
If you need granular control over SSO initiation (like customizing the trigger path, adding extra parameters to the AuthnRequest, or tying initiation to business logic), you can use this resolver directly in a custom controller or filter. It generates the proper redirect URL to the IDP on demand.
2. Step-by-Step for SP-Initiated SSO
Here’s how to implement SP-initiated SSO with Spring Security’s SAML2 SP support:
Step 1: Configure Your Relying Party (SP) Registration
First, define your Okta IDP details in a RelyingPartyRegistration (via Java config or properties):
@Bean public RelyingPartyRegistrationRepository relyingPartyRegistrationRepository() { RelyingPartyRegistration registration = RelyingPartyRegistrations .fromMetadataLocation("classpath:okta-metadata.xml") // Or use Okta's metadata URL .registrationId("okta") .entityId("your-sp-entity-id") .build(); return new InMemoryRelyingPartyRegistrationRepository(registration); }
Or via application.yml:
spring: security: saml2: relyingparty: okta: entity-id: your-sp-entity-id identityprovider: entity-id: https://your-okta-domain.com/oauth2/v1/metadata singlesignon: url: https://your-okta-domain.com/app/your-app-id/sso/saml binding: POST metadata-uri: https://your-okta-domain.com/app/your-app-id/sso/saml/metadata
Step 2: Configure the Security Filter Chain
Add saml2Login() to your SecurityFilterChain to enable SAML2 authentication and auto-register required filters:
@Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests(auth -> auth .anyRequest().authenticated() ) .saml2Login(saml2 -> saml2 // Optional: Customize post-login redirect logic .successHandler((request, response, authentication) -> { response.sendRedirect("/dashboard"); }) ); return http.build(); }
Step 3: Initiate SSO (Two Approaches)
Approach A: Use the Default Initiation Path
Spring Security automatically exposes an endpoint at /saml2/authenticate/{registrationId} (e.g., /saml2/authenticate/okta for our example). When a user visits this URL, the Saml2AuthenticationRequestRedirectFilter redirects them to Okta’s login page to start the flow.
Approach B: Custom SSO Trigger (Using Saml2AuthenticationRequestResolver)
For a custom endpoint (like /login/sso), create a controller that uses the resolver to generate the redirect:
@Controller public class SsoInitiationController { private final Saml2AuthenticationRequestResolver authenticationRequestResolver; public SsoInitiationController(Saml2AuthenticationRequestResolver authenticationRequestResolver) { this.authenticationRequestResolver = authenticationRequestResolver; } @GetMapping("/login/sso") public void initiateSso(HttpServletRequest request, HttpServletResponse response) throws IOException { // Resolve the redirect and send the user to Okta authenticationRequestResolver.resolve(request, response) .ifPresent(redirect -> redirect.sendRedirect(request, response)); } }
Step 4: Test the Flow
- Visit your custom SSO endpoint (e.g.,
/login/sso) or the default/saml2/authenticate/okta - You’ll be redirected to Okta’s login page
- After successful authentication, Okta sends a SAML response back to your SP’s Assertion Consumer Service (ACS) endpoint (default:
/login/saml2/sso/{registrationId}) - Spring Security validates the response, authenticates the user, and redirects to your configured success page
Key Notes
- Unlike the old
SAMLEntryPoint, you don’t need to explicitly register a filter for SSO initiation—saml2Login()handles most setup automatically. - For advanced customization (like adding relay state or modifying the AuthnRequest), you can provide a custom
Saml2AuthenticationRequestResolverbean or override it viasaml2Login().authenticationRequestResolver(...)in your filter chain config.
内容的提问来源于stack exchange,提问作者Madhusudana

