You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从spring-security-saml2-core升级至Spring Security SAML2 Service Provider:SAMLEntryPoint等效类及SP发起SSO流程咨询

Equivalent of SAMLEntryPoint in Spring Security SAML2 Service Provider & SP-Initiated SSO Steps

Great question! Moving from the legacy spring-security-saml2-core (now EOL) to Spring Security's native SAML2 SP support is a common upgrade, and it’s totally normal to look for equivalents to familiar components like SAMLEntryPoint. Let’s break this down clearly:

1. Equivalent to SAMLEntryPoint

The old SAMLEntryPoint existed to trigger SP-initiated SSO by redirecting users to the Identity Provider (Okta, in your case). In Spring Security’s built-in SAML2 support, there’s no 1:1 class replacement, but the core functionality is covered by two key components:

- Saml2AuthenticationRequestRedirectFilter

This filter is automatically registered when you configure saml2Login() in your security filter chain. It handles requests to the default SSO initiation path (typically /saml2/authenticate/{registrationId}) and redirects users to the IDP’s SSO endpoint with a valid SAML AuthnRequest.

- Saml2AuthenticationRequestResolver

If you need granular control over SSO initiation (like customizing the trigger path, adding extra parameters to the AuthnRequest, or tying initiation to business logic), you can use this resolver directly in a custom controller or filter. It generates the proper redirect URL to the IDP on demand.

2. Step-by-Step for SP-Initiated SSO

Here’s how to implement SP-initiated SSO with Spring Security’s SAML2 SP support:

Step 1: Configure Your Relying Party (SP) Registration

First, define your Okta IDP details in a RelyingPartyRegistration (via Java config or properties):

@Bean
public RelyingPartyRegistrationRepository relyingPartyRegistrationRepository() {
    RelyingPartyRegistration registration = RelyingPartyRegistrations
            .fromMetadataLocation("classpath:okta-metadata.xml") // Or use Okta's metadata URL
            .registrationId("okta")
            .entityId("your-sp-entity-id")
            .build();
    return new InMemoryRelyingPartyRegistrationRepository(registration);
}

Or via application.yml:

spring:
  security:
    saml2:
      relyingparty:
        okta:
          entity-id: your-sp-entity-id
          identityprovider:
            entity-id: https://your-okta-domain.com/oauth2/v1/metadata
            singlesignon:
              url: https://your-okta-domain.com/app/your-app-id/sso/saml
              binding: POST
            metadata-uri: https://your-okta-domain.com/app/your-app-id/sso/saml/metadata

Step 2: Configure the Security Filter Chain

Add saml2Login() to your SecurityFilterChain to enable SAML2 authentication and auto-register required filters:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
        .authorizeHttpRequests(auth -> auth
            .anyRequest().authenticated()
        )
        .saml2Login(saml2 -> saml2
            // Optional: Customize post-login redirect logic
            .successHandler((request, response, authentication) -> {
                response.sendRedirect("/dashboard");
            })
        );
    return http.build();
}

Step 3: Initiate SSO (Two Approaches)

Approach A: Use the Default Initiation Path

Spring Security automatically exposes an endpoint at /saml2/authenticate/{registrationId} (e.g., /saml2/authenticate/okta for our example). When a user visits this URL, the Saml2AuthenticationRequestRedirectFilter redirects them to Okta’s login page to start the flow.

Approach B: Custom SSO Trigger (Using Saml2AuthenticationRequestResolver)

For a custom endpoint (like /login/sso), create a controller that uses the resolver to generate the redirect:

@Controller
public class SsoInitiationController {

    private final Saml2AuthenticationRequestResolver authenticationRequestResolver;

    public SsoInitiationController(Saml2AuthenticationRequestResolver authenticationRequestResolver) {
        this.authenticationRequestResolver = authenticationRequestResolver;
    }

    @GetMapping("/login/sso")
    public void initiateSso(HttpServletRequest request, HttpServletResponse response) throws IOException {
        // Resolve the redirect and send the user to Okta
        authenticationRequestResolver.resolve(request, response)
                .ifPresent(redirect -> redirect.sendRedirect(request, response));
    }
}

Step 4: Test the Flow

  1. Visit your custom SSO endpoint (e.g., /login/sso) or the default /saml2/authenticate/okta
  2. You’ll be redirected to Okta’s login page
  3. After successful authentication, Okta sends a SAML response back to your SP’s Assertion Consumer Service (ACS) endpoint (default: /login/saml2/sso/{registrationId})
  4. Spring Security validates the response, authenticates the user, and redirects to your configured success page

Key Notes

  • Unlike the old SAMLEntryPoint, you don’t need to explicitly register a filter for SSO initiation—saml2Login() handles most setup automatically.
  • For advanced customization (like adding relay state or modifying the AuthnRequest), you can provide a custom Saml2AuthenticationRequestResolver bean or override it via saml2Login().authenticationRequestResolver(...) in your filter chain config.

内容的提问来源于stack exchange,提问作者Madhusudana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 19:02:41