You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何强制ITfoxTec SAML服务端使用HTTP-POST而非HTTP-Redirect?

强制ITfoxTec SAML使用HTTP-POST绑定的SingleSignOnService地址

我的IdP提供了两个SingleSignOnService地址:

return (<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://rengirtu.sciedu.jp/sub/Redirect/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://rengirtu.sciedu.jp/sub/POST/SSO"/>
)

但我的SP Web应用连接时总是自动使用HTTP-Redirect地址,请问如何强制ITfoxTec使用HTTP-POST的地址?以下是我当前使用的Login方法代码:

[Route("Login")]
public IActionResult Login(string returnUrl = null)
{
    var binding = new Saml2PostBinding();
    binding.SetRelayStateQuery(new Dictionary<string, string> { { relayStateReturnUrl, returnUrl ?? Url.Content("~/" ) } });

    return binding.Bind(new Saml2AuthnRequest(config)
    {
        //ForceAuthn = true,
        //Subject = new Subject { NameID = new NameID { ID = "Japan_Portal" } },
        //NameIdPolicy = new NameIdPolicy { AllowCreate = true, Format = "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" },
        //Extensions = new AppExtensions(),
        //RequestedAuthnContext = new RequestedAuthnContext
        //{
        //    Comparison = AuthnContextComparisonTypes.Exact,
        //    AuthnContextClassRef = new string[] { AuthnContextClassTypes.PasswordProtectedTransport.OriginalString },
        //},
    }).ToActionResult();
}

解决方案

要强制指定使用HTTP-POST的SingleSignOnService地址,直接在Saml2AuthnRequest对象中手动设置Destination属性即可,覆盖从IdP元数据自动获取的地址。

修改后的完整代码如下:

[Route("Login")]
public IActionResult Login(string returnUrl = null)
{
    var binding = new Saml2PostBinding();
    binding.SetRelayStateQuery(new Dictionary<string, string> { { relayStateReturnUrl, returnUrl ?? Url.Content("~/" ) } });

    return binding.Bind(new Saml2AuthnRequest(config)
    {
        // 手动指定IdP的HTTP-POST绑定SSO地址
        Destination = "https://rengirtu.sciedu.jp/sub/POST/SSO",
        //ForceAuthn = true,
        //Subject = new Subject { NameID = new NameID { ID = "Japan_Portal" } },
        //NameIdPolicy = new NameIdPolicy { AllowCreate = true, Format = "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" },
        //Extensions = new AppExtensions(),
        //RequestedAuthnContext = new RequestedAuthnContext
        //{
        //    Comparison = AuthnContextComparisonTypes.Exact,
        //    AuthnContextClassRef = new string[] { AuthnContextClassTypes.PasswordProtectedTransport.OriginalString },
        //},
    }).ToActionResult();
}

这种方式直接精准指定目标地址,是最可靠的解决办法。你也可以检查IdP元数据的加载逻辑,调整绑定优先级,但手动设置Destination更直接可控。

内容的提问来源于stack exchange,提问作者SkyeBoniwell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 14:10:21