You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何调用采用ADFS/SAML认证的SharePoint本地API?求Java示例代码

Java客户端适配ADFS认证访问SharePoint本地API示例

核心依赖

若使用Maven管理项目,需引入以下依赖:

<dependencies>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-saml2-core</artifactId>
        <version>2.0.1.RELEASE</version>
    </dependency>
    <dependency>
        <groupId>org.apache.httpcomponents</groupId>
        <artifactId>httpclient</artifactId>
        <version>4.5.14</version>
    </dependency>
    <dependency>
        <groupId>com.nimbusds</groupId>
        <artifactId>nimbus-jose-jwt</artifactId>
        <version>9.23</version>
    </dependency>
</dependencies>

示例代码

1. 获取ADFS的SAML断言

负责向ADFS服务器发起认证请求,获取有效SAML断言:

import com.nimbusds.saml2.core.Assertion;
import com.nimbusds.saml2.core.Response;
import com.nimbusds.saml2.core.impl.ResponseParser;
import org.apache.http.HttpEntity;
import org.apache.http.HttpResponse;
import org.apache.http.client.HttpClient;
import org.apache.http.client.methods.HttpPost;
import org.apache.http.entity.StringEntity;
import org.apache.http.impl.client.HttpClients;
import org.apache.http.util.EntityUtils;

import java.io.IOException;
import java.net.URI;
import java.net.URISyntaxException;
import java.text.ParseException;

public class ADFSAuthentication {

    private static final String ADFS_ENDPOINT = "https://your-adfs-server/adfs/ls/idpinitiatedsignon.aspx?loginToRp=urn:sharepoint:your-site";
    private static final String USERNAME = "your-domain\\username";
    private static final String PASSWORD = "your-password";

    public static Assertion getSAMLAssertion() throws IOException, URISyntaxException, ParseException {
        HttpClient client = HttpClients.createDefault();
        HttpPost post = new HttpPost(new URI(ADFS_ENDPOINT));

        // 构造ADFS表单登录参数
        String formData = String.format("UserName=%s&Password=%s&AuthMethod=FormsAuthentication", USERNAME, PASSWORD);
        post.setEntity(new StringEntity(formData));
        post.setHeader("Content-Type", "application/x-www-form-urlencoded");

        HttpResponse response = client.execute(post);
        HttpEntity entity = response.getEntity();
        String responseBody = EntityUtils.toString(entity);

        // 解析SAML响应提取断言
        ResponseParser parser = new ResponseParser();
        Response samlResponse = parser.parse(responseBody);
        return samlResponse.getAssertions().get(0);
    }
}

2. 携带SAML断言访问SharePoint API

将获取到的SAML断言放入请求头,发起API调用:

import org.apache.http.HttpEntity;
import org.apache.http.HttpResponse;
import org.apache.http.client.HttpClient;
import org.apache.http.client.methods.HttpGet;
import org.apache.http.impl.client.HttpClients;
import org.apache.http.util.EntityUtils;

import java.io.IOException;
import com.nimbusds.saml2.core.Assertion;

public class SharePointApiClient {

    private static final String SHAREPOINT_API_URL = "https://your-sharepoint-site/_api/web/lists/getbytitle('Documents')/items";

    public static void fetchSharePointData(Assertion samlAssertion) throws IOException {
        HttpClient client = HttpClients.createDefault();
        HttpGet get = new HttpGet(SHAREPOINT_API_URL);

        // 将SAML断言编码后放入Authorization头
        String encodedAssertion = samlAssertion.toXMLString();
        String authHeader = "SAML " + java.util.Base64.getEncoder().encodeToString(encodedAssertion.getBytes());
        get.setHeader("Authorization", authHeader);
        get.setHeader("Accept", "application/json;odata=verbose");

        HttpResponse response = client.execute(get);
        HttpEntity entity = response.getEntity();
        String apiResponse = EntityUtils.toString(entity);

        // 处理并输出API返回数据
        System.out.println("SharePoint API Response: " + apiResponse);
    }

    public static void main(String[] args) {
        try {
            Assertion assertion = ADFSAuthentication.getSAMLAssertion();
            fetchSharePointData(assertion);
        } catch (Exception e) {
            e.printStackTrace();
        }
    }
}

关键注意事项

  • 替换代码中ADFS_ENDPOINT、USERNAME、PASSWORD、SHAREPOINT_API_URL为实际环境参数
  • 确保ADFS管理控制台已将你的应用配置为合法信赖方(RP)
  • 测试环境若遇SSL证书验证问题,可临时关闭HttpClient的SSL校验(生产环境必须配置可信证书)
  • 生产环境建议添加SAML断言缓存逻辑,减少重复认证请求

内容的提问来源于stack exchange,提问作者Ranjit Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 20:05:15