在Auth控制器登录路由使用ITfoxtec Identity SAML 2.0时遇空引用异常
SAML初始化时ArgumentNullException异常排查与解决
问题根源
你遇到的System.ArgumentNullException: 'Value cannot be null. Parameter name: uriString'异常,核心原因是Saml2Configuration的Issuer属性未初始化。
在你的ConfigureSAML方法中,实例化Saml2Configuration后直接执行Config.AllowedAudienceUris.Add(Config.Issuer),此时Config.Issuer默认是null——因为你没有显式设置该属性。后续创建Saml2AuthnRequest时,框架需要使用Issuer作为合法URI参数,空值直接触发了这个异常。
修正方案
在添加允许的受众URI之前,先为Config.Issuer赋值(值为你的应用的实体ID,通常是一个唯一的URI,比如你的应用的SAML服务端点地址)。
修正后的ConfigureSAML方法代码如下:
public static void ConfigureSAML() { Config = new Saml2Configuration(); RelayStateReturnUrl = "relayStateReturnUrl"; // 先设置应用自身的Issuer(实体ID) Config.Issuer = "https://yourapp.example.com/saml"; // 替换为你的应用实际标识URI // 添加Issuer到允许的受众URI列表 Config.AllowedAudienceUris.Add(Config.Issuer); // Set the SAML identity provider entity ID Config.AllowedIssuer = "https://login.oregonstate.edu/idp/shibboleth"; // Set the SAML single sign-on endpoint URL (redirect binding) Config.SingleSignOnDestination = new Uri("https://login.oregonstate.edu/idp/profile/SAML2/Redirect/SSO"); // Certificate used to sign outgoing SAML requests. We send the public key to the IdP with our SAML requests Config.SigningCertificate = LoadCertificate("path/to/signing/certificate"); // Certificate used for validating the incoming SAML response from the IdP Config.SignatureValidationCertificates.Add(LoadCertificate("path/to/certificate")); }
额外注意事项
- 确保
Config.Issuer的值是符合URI格式的有效字符串,不能为null或空 - 如果你不确定应用的实体ID,可以参考IdP(这里是Oregon State的Shibboleth)的配置文档,确认需要填写的应用标识
内容的提问来源于stack exchange,提问作者Sankalp Patil
相关产品推荐
相关产品推荐

