SimpleSAMLphp单点登出功能失效问题求助
SimpleSAMLphp单点登录正常但登出功能失效求助
我是SimpleSAMLphp新手,按第三方要求搭建了SSO单点登录环境,已完成元数据交换,目前SSO登录正常,但登出功能无法实现。尝试多种网上方案均失败,执行登出代码后仍能访问页面,推测是Cookie未被清除。
我的登出代码:
$as = new SimpleSAML_Auth_Simple('default-sp'); $as = \SimpleSAML\Session::getSessionFromRequest(); $as->logout(array( 'ReturnTo' => '[3rd party home page]', 'ReturnStateParam' => 'LogoutState', 'ReturnStateStage' => 'MyLogoutState', )); SimpleSAML_Session::getSessionFromRequest()->cleanup();
相关配置文件
saml20-idp-remote.php
$metadata['https://[mydomain]/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://[mydomain]/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://[mydomain]/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://[mydomain]/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => '[somerandomkey]', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'myemail@gmail.com', 'contactType' => 'technical', 'givenName' => 'myname', ], ], ];
saml20-sp-remote.php
$metadata['https://[3rdparty domain]/module.php/saml/sp/metadata.php/default-sp'] = [ 'entityid' => 'https://[3rdparty domain]/module.php/saml/sp/metadata.php/default-sp', 'contacts' => [ [ 'contactType' => 'technical', 'givenName' => 'Administrator', 'emailAddress' => [ 'support@3rdpartydomain.com', ], ], ], 'metadata-set' => 'saml20-sp-remote', 'AssertionConsumerService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml2-acs.php/default-sp', 'index' => 0, ], [ 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:browser-post', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml1-acs.php/default-sp', 'index' => 1, ], [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml2-acs.php/default-sp', 'index' => 2, ], [ 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:artifact-01', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml1-acs.php/default-sp/artifact', 'index' => 3, ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml2-logout.php/default-sp', ], [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:SOAP', 'Location' => 'https://[3rdparty domain]/module.php/saml/sp/saml2-logout.php/default-sp', ], ], ];
authsources.php
'default-sp' => [ 'saml:SP', 'entityID' => 'https://[3rdparty domain]/module.php/saml/sp/metadata.php/default-sp', 'idp' => 'https://[mydomain]/simplesaml/saml2/idp/', 'discoURL' => null, ],
我猜测是authsources.php配置有误,但因对SAML不熟悉,无法定位问题,恳请帮忙排查,谢谢!
内容的提问来源于stack exchange,提问作者Reyn
相关产品推荐
相关产品推荐

