如何修改Sustainsys SAML2中AttributeConsumingService的index值?
解决Sustainsys SAML2修改AttributeConsumingService默认index的问题
方法一:通过web.config配置直接指定
在Sustainsys.Saml2的配置节点中,显式配置AttributeConsumingServices,设定index为1并标记为默认。示例配置如下:<sustainsys.saml2 entityId="你的SP实体ID" returnUrl="你的回调地址"> <attributeConsumingServices> <add index="1" isDefault="true"> <serviceNames> <add value="SP" lang="en" /> </serviceNames> <requestedAttributes> <add name="所需属性名称" isRequired="true" /> <!-- 其他需要请求的属性配置 --> </requestedAttributes> </add> </attributeConsumingServices> <!-- 其他配置节点(如identityProviders等) --> </sustainsys.saml2>配置完成后,生成的元数据中默认的AttributeConsumingService index会自动变为1,注意移除原有默认生成的index=0配置,避免冲突。
方法二:通过代码自定义元数据生成
如果配置文件方式未生效,可通过代码拦截元数据生成过程修改属性。在应用启动时(比如Global.asax的Application_Start方法)添加以下代码:using Sustainsys.Saml2.Metadata; using Sustainsys.Saml2.WebSso; protected void Application_Start() { var samlModule = Saml2AuthenticationModule.Current; if (samlModule != null) { samlModule.MetadataCreated += (sender, e) => { var defaultService = e.EntityDescriptor.SpssoDescriptor.AttributeConsumingServices.FirstOrDefault(s => s.IsDefault); if (defaultService != null) { defaultService.Index = 1; // 处理index冲突,将原index=1的服务调整为非默认 var existingIndex1 = e.EntityDescriptor.SpssoDescriptor.AttributeConsumingServices.FirstOrDefault(s => s.Index == 1 && s != defaultService); if (existingIndex1 != null) { existingIndex1.Index = 0; existingIndex1.IsDefault = false; } } }; } }这段代码会在元数据生成时,将默认的AttributeConsumingService的index改为1,并处理可能存在的index重复问题。
验证修改结果
启动应用后,访问元数据端点(通常为https://你的域名/Saml2/Metadata),查看生成的XML中AttributeConsumingService的index是否已改为1且isDefault="true"。
内容的提问来源于stack exchange,提问作者Jerker Pihl
相关产品推荐
相关产品推荐

