You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 6集成Sustainsys.Saml2,从IdP返回后User/Claims为空

.NET 6集成Sustainsys.Saml2后User及Claims为空问题

我正尝试在新的.NET 6项目中集成Sustainsys.Saml2,但在ACS调用完成后遇到User及claims为空的问题。日志显示已成功处理SAML响应并认证用户,但User.Identity未被填充,IsAuthenticated属性也未设置。我的目标是让应用作为单个外部IdP的SP,不清楚问题所在,寻求帮助。

相关信息

1. 框架与包

使用.NET 6.0,相关包见截图(原提问附带截图,此处省略)

2. Program.cs配置代码

builder.Services.AddIdentity<ApplicationUser, IdentityRole>()
    .AddEntityFrameworkStores<{...context...}>()
    .AddDefaultTokenProviders();

builder.Services.AddAuthentication(opt =>
{
    // Default scheme that maintains session is cookies.
    opt.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;

    // If there's a challenge to sign in, use the Saml2 scheme.
    opt.DefaultChallengeScheme = Saml2Defaults.Scheme;
})
.AddCookie()
.AddSaml2(opt =>
{
    // Us; the Service Provider
    opt.SPOptions.EntityId = new EntityId("https://localhost:34287/Saml2");

    // Single logout messages should be signed according to the SAML2 standard, so we need
    // to add a certificate for our app to sign logout messages with to enable logout functionality.
    opt.SPOptions.ServiceCertificates.Add(new X509Certificate2("Sustainsys.Saml2.Tests.pfx"));

    // Them; the Identify Provider
    opt.IdentityProviders.Add(

        // Fake IdP for testing
        new IdentityProvider(new EntityId("https://stubidp.sustainsys.com/Metadata"), opt.SPOptions)
        {
            LoadMetadata = true
        });
});

3. AccountController代码

public AccountController(IConfiguration configuration, SignInManager<ApplicationUser> signInManager, ILogger<AccountController> logger)
{
    _configuration = configuration;
    _signInManager = signInManager;
    _logger = logger;
}

[HttpPost]
[ValidateAntiForgeryToken]
public IActionResult Login()
{
    // Automatic handling is to redirect back to same page after successful
    // login. We don't want that on explicit login.
    var props = new AuthenticationProperties
    {
        RedirectUri = "/"
    };

    return Challenge(props, Saml2Defaults.Scheme);
}

日志信息

点击登录按钮后,Saml2日志显示:

info: Sustainsys.Saml2.AspNetCore2.Saml2Handler[0]
      Initiating login to https://stubidp.sustainsys.com/Metadata
info: Sustainsys.Saml2.AspNetCore2.Saml2Handler[0]
      Successfully processed SAML response id84814e90fa344d05876556797416dc41 and authenticated AdminAlmighty

内容的提问来源于stack exchange,提问作者Nick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 07:10:23