You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用itfoxtec-identity-saml2时IdP返回“无法解码”错误的调试求助

调试SAML SP的“Unable to Decode”错误

我基于.NET Core搭建SAML服务提供商(SP)Web应用,使用itfoxtec-identity-saml2库。目前已能连接到身份提供商(IdP),但IdP返回“Unable to Decode”错误。

错误出现在AuthController.cs的以下代码发送请求时:

[Route("Login")]
public IActionResult Login(string? returnUrl = null)
{
    var binding = new Saml2RedirectBinding();
    binding.SetRelayStateQuery(new Dictionary<string, string> { { relayStateReturnUrl, returnUrl ?? Url.Content("~/") } });

    return binding.Bind(new Saml2AuthnRequest(config)).ToActionResult();
}

请问有哪些方法可以帮助调试此问题?


收集到的浏览器数据

请求头

GET https://singlesignon.lowell.edu/idp/profile/SAML2/POST/SSO?SAMLRequest=fJBBb4MwDIX%2FCso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589%2Bzw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh%2B%2B%2FKsRMqVDw7d4Cbyl%2Fkf0QAm4OgsSfa7lnxIaaoqL6%2B0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG%2BoqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA%2B8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E%2Bv7A%2BmaeyR1vxi6Y0TWiSdnrRnQhYY96L%2Fl4z%2B7bwAAAP%2F%2FAwA%3D&RelayState=ReturnUrl%3D%252F HTTP/1.1
sec-ch-ua: "Not.A/Brand";v="8", "Chromium";v="114", "Google Chrome";v="114"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Windows"
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: cross-site
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://localhost:7133/
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Cookie: shib_idp_session=dcefe3bd1b8e866da71b733a98a96a49ccb9d15f1481a74ba447757dcf86a7cf; JSESSIONID=D9B5D82C717EF64AE5D4AED9446A1042

HTTP/1.1 400 Bad Request
Server: Apache-Coyote/1.1
Cache-Control: no-store
Content-Type: text/html;charset=utf-8
Content-Length: 1655
Date: Wed, 28 Jun 2023 13:59:31 GMT
Connection: close

负载

SAMLRequest: fJBBb4MwDIX/Cso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589+zw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh++/KsRMqVDw7d4Cbyl/kf0QAm4OgsSfa7lnxIaaoqL6+0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG+oqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA+8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E+v7A+maeyR1vxi6Y0TWiSdnrRnQhYY96L/l4z+7bwAAAP//AwA=
RelayState: ReturnUrl=%2F

Chrome SAML Tracer数据

<saml2p:AuthnRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
                     xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
                     ID="_76e6448i-79a9-475a-9203-be84b1501496"
                     Version="2.0"
                     IssueInstant="2023-06-28T13:55:08.731Z"
                     Destination="https://singlesignon.lowell.edu/idp/profile/SAML2/POST/SSO"
                     >
    <saml2:Issuer>DevConnector</saml2:Issuer>
</saml2p:AuthnRequest>

GET
SAMLRequest: fJBBb4MwDIX/Cso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589+zw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh++/KsRMqVDw7d4Cbyl/kf0QAm4OgsSfa7lnxIaaoqL6+0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG+oqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA+8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E+v7A+maeyR1vxi6Y0TWiSdnrRnQhYY96L/l4z+7bwAAAP//AwA=
RelayState: ReturnUrl=%2F

调试建议

  • 匹配绑定类型与IdP端点:你当前使用Saml2RedirectBinding(GET请求),但请求的IdP端点是/SAML2/POST/SSO——这是POST绑定的专属端点。Redirect绑定需要对应IdP的Redirect SSO端点(通常类似/SAML2/Redirect/SSO),绑定类型与端点不匹配是解码失败的核心原因。
  • 手动验证SAMLRequest编码流程:
    1. 对SAMLRequest值先做Base64解码,再用DEFLATE解压(Redirect绑定要求压缩XML),检查输出的XML是否完整、格式合法。
    2. 确认URL编码正确性:Redirect绑定会对Base64结果做URL编码,检查+是否被转义为%2B(从请求头看已转义,但可二次确认)。
  • 补全AuthnRequest必要元素:从SAML Tracer的输出看,你的AuthnRequest缺少NameIDPolicy、ProtocolBinding等部分IdP要求的必填项。可以参考示例补充:
    var authnRequest = new Saml2AuthnRequest(config)
    {
        NameIDPolicy = new Saml2NameIDPolicy { Format = Saml2NameIDFormat.Unspecified, AllowCreate = true },
        ProtocolBinding = Saml2BindingTypes.HttpPost,
    };
    
  • 获取IdP侧详细日志:联系IdP管理员,获取解码失败的具体日志(比如是Base64解码错误、DEFLATE解压失败还是XML格式问题),直接定位故障点。
  • 对比官方示例配置:将你的代码和itfoxtec-identity-saml2的官方示例项目对比,检查Saml2Configuration中的IdP元数据、SP实体ID等配置是否正确,避免遗漏必要项。
  • 修正AuthnRequest的Destination:当前AuthnRequest的Destination指向POST端点,与Redirect绑定冲突,必须修改为对应Redirect绑定的IdP端点地址。

内容的提问来源于stack exchange,提问作者SkyeBoniwell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 02:00:00