You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Auth控制器登录路由使用ITfoxtec Identity SAML 2.0时遇空引用异常

SAML初始化时ArgumentNullException异常排查与解决

问题根源

你遇到的System.ArgumentNullException: 'Value cannot be null. Parameter name: uriString'异常,核心原因是Saml2Configuration的Issuer属性未初始化。

在你的ConfigureSAML方法中,实例化Saml2Configuration后直接执行Config.AllowedAudienceUris.Add(Config.Issuer),此时Config.Issuer默认是null——因为你没有显式设置该属性。后续创建Saml2AuthnRequest时,框架需要使用Issuer作为合法URI参数,空值直接触发了这个异常。

修正方案

在添加允许的受众URI之前,先为Config.Issuer赋值(值为你的应用的实体ID,通常是一个唯一的URI,比如你的应用的SAML服务端点地址)。

修正后的ConfigureSAML方法代码如下:

public static void ConfigureSAML()
{
    Config = new Saml2Configuration();

    RelayStateReturnUrl = "relayStateReturnUrl";

    // 先设置应用自身的Issuer(实体ID)
    Config.Issuer = "https://yourapp.example.com/saml"; // 替换为你的应用实际标识URI

    // 添加Issuer到允许的受众URI列表
    Config.AllowedAudienceUris.Add(Config.Issuer);

    // Set the SAML identity provider entity ID
    Config.AllowedIssuer = "https://login.oregonstate.edu/idp/shibboleth";

    // Set the SAML single sign-on endpoint URL (redirect binding)
    Config.SingleSignOnDestination = new Uri("https://login.oregonstate.edu/idp/profile/SAML2/Redirect/SSO");

    // Certificate used to sign outgoing SAML requests. We send the public key to the IdP with our SAML requests
    Config.SigningCertificate = LoadCertificate("path/to/signing/certificate");

    // Certificate used for validating the incoming SAML response from the IdP
    Config.SignatureValidationCertificates.Add(LoadCertificate("path/to/certificate"));
}

额外注意事项

  • 确保Config.Issuer的值是符合URI格式的有效字符串,不能为null或空
  • 如果你不确定应用的实体ID,可以参考IdP(这里是Oregon State的Shibboleth)的配置文档,确认需要填写的应用标识

内容的提问来源于stack exchange,提问作者Sankalp Patil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:02:53