You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot3/Vaadin24迁移:SAML登录后403权限问题求助

Spring Boot 3 + Vaadin 24 SAML 迁移后 /saml/SSO 403 问题修复

1. 适配Spring Security 6的新配置逻辑(替代WebSecurityConfigurerAdapter)

Spring Boot 3弃用了WebSecurityConfigurerAdapter,改用SecurityFilterChain配置安全规则,结合Vaadin 24的特殊请求处理,必须同时放行SAML端点和Vaadin内部请求,还要排除CSRF对SAML的限制(F5的SAML请求通常不带CSRF Token):

@Configuration
public class SecurityConfig extends VaadinWebSecurity {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        // 继承Vaadin默认安全配置,避免拦截Vaadin自身请求
        super.configure(http);

        http
            // 排除SAML端点的CSRF校验
            .csrf(csrf -> csrf.ignoringRequestMatchers("/saml/**"))
            // 授权规则:SAML相关路径全部放行
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/saml/**").permitAll()
                // 确保Vaadin默认白名单路径也被放行(如/VAADIN/**、/heartbeat/**等)
                .requestMatchers(VaadinWebSecurity.getDefaultHttpWhiteList()).permitAll()
                // 其余请求需认证
                .anyRequest().authenticated()
            )
            // 配置SAML2登录,登录处理地址需和ACS地址一致
            .saml2Login(saml2 -> saml2
                .loginProcessingUrl("/saml/SSO")
            )
            // 配置SAML2登出
            .saml2Logout(saml2 -> saml2
                .logoutSuccessUrl("/")
            );
    }

    // 配置RelyingPartyRegistration,确保ACS地址与F5完全匹配
    @Bean
    public RelyingPartyRegistration relyingPartyRegistration() {
        return RelyingPartyRegistration.withRegistrationId("f5-idp")
            .entityId("http://localhost:8080/myAppName/saml/metadata")
            .assertionConsumerServiceLocation("http://localhost:8080/myAppName/saml/SSO")
            // 补充F5 IDP的元数据地址或实体ID等配置
            .idpEntityId("F5-IDP-ENTITY-ID")
            .idpWebSsoUrl("http://f5-idp-url/saml/sso")
            .build();
    }
}

2. 严格校验ACS地址与F5配置的一致性

F5对请求路径和参数匹配要求苛刻,必须保证assertionConsumerServiceLocation的配置和F5后台的ACS地址完全一致:

  • 检查上下文路径myAppName是否正确(注意不要带多余引号)
  • 路径/saml/SSO的大小写、斜杠要完全匹配
  • 协议(http)、端口必须和内网访问地址一致

3. 排查403的具体触发原因

如果以上配置仍无效,开启Spring Security DEBUG日志定位问题:
在application.properties中添加:

logging.level.org.springframework.security=DEBUG

查看日志中FilterChainProxy的输出,确认请求/saml/SSO时经过的过滤器链,找到返回403的具体过滤器(比如CSRF过滤器、授权过滤器),针对性调整规则。

内容的提问来源于stack exchange,提问作者supernicky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 09:59:52