OpenSAML 4中如何将SAML Assertion转换为字符串
OpenSAML 4.1.1 序列化Assertion为字符串的实现方案
OpenSAML 4.x版本重构了原有工具类的包结构,旧版的XMLHelper类已被移除,DOM节点转XML字符串的能力迁移到了Shibboleth java-support模块的SerializeSupport类中,直接替换对应调用即可,无需自行实现DOM序列化逻辑。
修改步骤
- 替换导入依赖,删除旧版
XMLHelper的导入语句,新增以下导入:
import net.shibboleth.utilities.java.support.xml.SerializeSupport;
- 将原代码中调用
XMLHelper.nodeToString的逻辑替换为SerializeSupport的同名方法,修改后的可运行代码如下:
SAMLInputContainer input = new SAMLInputContainer(); input.strIssuer = "http://synesty.com"; input.strNameID = "UserJohnSmith"; input.strNameQualifier = "My Website"; input.sessionId = "abcdedf1234567"; Map<String,String> customAttributes = new HashMap<String, String>(); customAttributes.put("FirstName", "John"); customAttributes.put("LastName", "Smith"); customAttributes.put("Email", "john.smith@yahoo.com"); customAttributes.put("PhoneNumber", "76373898998"); customAttributes.put("Locality", "USA"); customAttributes.put("Username", "John.Smith"); input.attributes = customAttributes; Assertion assertion = GenSAMLAssertion.buildDefaultAssertion(input); AssertionMarshaller marshaller = new AssertionMarshaller(); assert assertion != null; Element plaintextElement = marshaller.marshall(assertion); // 替换旧版XMLHelper的调用 String originalAssertionString = SerializeSupport.nodeToString(plaintextElement); System.out.println("Assertion String: " + originalAssertionString);
可选配置
SerializeSupport.nodeToString提供重载参数支持自定义输出格式:
- 第二个参数:布尔值,控制是否输出XML声明头(
<?xml version="1.0" encoding="UTF-8"?>) - 第三个参数:布尔值,控制是否对XML做缩进格式化,方便调试阅读
调用示例:
// 输出带XML声明、自动缩进格式化的断言字符串 String prettyPrintAssertion = SerializeSupport.nodeToString(plaintextElement, true, true);
注意:不建议自行编写
javax.xml.transform相关逻辑实现DOM转字符串,官方工具类已经兼容了SAML命名空间输出、特殊字符转义、XML规范对齐等细节,自行实现很容易生成不符合SAML 2.0规范的报文,导致对接校验失败。
内容的提问来源于stack exchange,提问作者Connie DeCinko
相关产品推荐
相关产品推荐

