使用itfoxtec-identity-saml2时IdP返回“无法解码”错误的调试求助
调试SAML SP的“Unable to Decode”错误
我基于.NET Core搭建SAML服务提供商(SP)Web应用,使用itfoxtec-identity-saml2库。目前已能连接到身份提供商(IdP),但IdP返回“Unable to Decode”错误。
错误出现在AuthController.cs的以下代码发送请求时:
[Route("Login")] public IActionResult Login(string? returnUrl = null) { var binding = new Saml2RedirectBinding(); binding.SetRelayStateQuery(new Dictionary<string, string> { { relayStateReturnUrl, returnUrl ?? Url.Content("~/") } }); return binding.Bind(new Saml2AuthnRequest(config)).ToActionResult(); }
请问有哪些方法可以帮助调试此问题?
收集到的浏览器数据
请求头
GET https://singlesignon.lowell.edu/idp/profile/SAML2/POST/SSO?SAMLRequest=fJBBb4MwDIX%2FCso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589%2Bzw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh%2B%2B%2FKsRMqVDw7d4Cbyl%2Fkf0QAm4OgsSfa7lnxIaaoqL6%2B0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG%2BoqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA%2B8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E%2Bv7A%2BmaeyR1vxi6Y0TWiSdnrRnQhYY96L%2Fl4z%2B7bwAAAP%2F%2FAwA%3D&RelayState=ReturnUrl%3D%252F HTTP/1.1 sec-ch-ua: "Not.A/Brand";v="8", "Chromium";v="114", "Google Chrome";v="114" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Referer: https://localhost:7133/ Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: shib_idp_session=dcefe3bd1b8e866da71b733a98a96a49ccb9d15f1481a74ba447757dcf86a7cf; JSESSIONID=D9B5D82C717EF64AE5D4AED9446A1042 HTTP/1.1 400 Bad Request Server: Apache-Coyote/1.1 Cache-Control: no-store Content-Type: text/html;charset=utf-8 Content-Length: 1655 Date: Wed, 28 Jun 2023 13:59:31 GMT Connection: close
负载
SAMLRequest: fJBBb4MwDIX/Cso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589+zw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh++/KsRMqVDw7d4Cbyl/kf0QAm4OgsSfa7lnxIaaoqL6+0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG+oqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA+8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E+v7A+maeyR1vxi6Y0TWiSdnrRnQhYY96L/l4z+7bwAAAP//AwA= RelayState: ReturnUrl=%2F
Chrome SAML Tracer数据
<saml2p:AuthnRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_76e6448i-79a9-475a-9203-be84b1501496" Version="2.0" IssueInstant="2023-06-28T13:55:08.731Z" Destination="https://singlesignon.lowell.edu/idp/profile/SAML2/POST/SSO" > <saml2:Issuer>DevConnector</saml2:Issuer> </saml2p:AuthnRequest> GET SAMLRequest: fJBBb4MwDIX/Cso9JCRQIAKkar1U2tRqVDvsMqU0VZEgyWIj7ecvdDuslx3t589+zw3oeRJebRe82VfzuRjA5GueLKgfpSVLsMppGEFZPRtQOKh++/KsRMqVDw7d4Cbyl/kf0QAm4OgsSfa7lnxIaaoqL6+0rHVN87LQtBZc0rOp8nNW8CyvNyR5MwEi05K4IoIAi9lbQG0xtriQlG+oqE6ZVEWheJWWMnsnyS6mGa1er7XkhuhBMeajA+8Cpn5ETM1lYePFs5jkOk6GrT4FOx76E+v7A+maeyR1vxi6Y0TWiSdnrRnQhYY96L/l4z+7bwAAAP//AwA= RelayState: ReturnUrl=%2F
调试建议
- 匹配绑定类型与IdP端点:你当前使用
Saml2RedirectBinding(GET请求),但请求的IdP端点是/SAML2/POST/SSO——这是POST绑定的专属端点。Redirect绑定需要对应IdP的Redirect SSO端点(通常类似/SAML2/Redirect/SSO),绑定类型与端点不匹配是解码失败的核心原因。 - 手动验证SAMLRequest编码流程:
- 对
SAMLRequest值先做Base64解码,再用DEFLATE解压(Redirect绑定要求压缩XML),检查输出的XML是否完整、格式合法。 - 确认URL编码正确性:Redirect绑定会对Base64结果做URL编码,检查
+是否被转义为%2B(从请求头看已转义,但可二次确认)。
- 对
- 补全AuthnRequest必要元素:从SAML Tracer的输出看,你的AuthnRequest缺少
NameIDPolicy、ProtocolBinding等部分IdP要求的必填项。可以参考示例补充:var authnRequest = new Saml2AuthnRequest(config) { NameIDPolicy = new Saml2NameIDPolicy { Format = Saml2NameIDFormat.Unspecified, AllowCreate = true }, ProtocolBinding = Saml2BindingTypes.HttpPost, }; - 获取IdP侧详细日志:联系IdP管理员,获取解码失败的具体日志(比如是Base64解码错误、DEFLATE解压失败还是XML格式问题),直接定位故障点。
- 对比官方示例配置:将你的代码和
itfoxtec-identity-saml2的官方示例项目对比,检查Saml2Configuration中的IdP元数据、SP实体ID等配置是否正确,避免遗漏必要项。 - 修正AuthnRequest的Destination:当前AuthnRequest的Destination指向POST端点,与Redirect绑定冲突,必须修改为对应Redirect绑定的IdP端点地址。
内容的提问来源于stack exchange,提问作者SkyeBoniwell
相关产品推荐
相关产品推荐

