Spring Boot saml2login如何在AuthenticationSuccessHandler获取IDP实体ID
解决方法
Spring Security 新版 saml2login 模块已经封装好了IDP相关元数据,无需自行解析解密SAML响应XML,直接将Authentication对象强转为Saml2AuthenticationToken类型即可获取IDP实体ID,示例代码如下:
import org.springframework.security.saml2.provider.service.authentication.Saml2AuthenticationToken; import org.springframework.security.saml2.provider.service.registration.RelyingPartyRegistration; // 业务逻辑位置 if (authentication instanceof Saml2AuthenticationToken samlToken) { RelyingPartyRegistration relyingPartyRegistration = samlToken.getRelyingPartyRegistration(); // 直接获取IDP实体ID,对应旧版samlCred.getRemoteEntityID()返回值 String idpEntityId = relyingPartyRegistration.getAssertingPartyDetails().getEntityId(); return getCustomerService().getActiveCustomerBySamlEntityId(idpEntityId) .filter(c -> c != null && c.isFullyActive()); }
扩展说明
- 所有IDP相关的配置信息都可以从
RelyingPartyRegistration对象获取,包括IDP的单点登录地址、签名证书、加密配置等,无需额外查询存储的配置 Saml2AuthenticatedPrincipal本身仅存储用户身份属性,不包含IDP元数据,通过认证Token获取元数据是官方推荐的标准实现方式- 如果你需要在业务层更方便的获取IDP信息,可以自定义SAML认证转换器,将IDP实体ID提前存入用户Principal的属性列表或者权限集合中
内容的提问来源于stack exchange,提问作者csyperski
相关产品推荐
相关产品推荐

