ITFoxtec.Identity示例中IdP-initiated与MVC协同运行及配置咨询
ITFoxtec.Identity.Saml2 实现IdP-initiated SSO 操作指南
- 官方默认把
IdPInitiatedController放在SP示例项目里,是为了演示「SP侧触发IdP-initiated流程」的特殊场景,常规IdP-initiated流程确实应该从IdP侧发起,你把Controller移到TestIdPCore的操作是对的。
步骤1:IdP侧(TestIdPCore项目)配置
- 先确认你已经把SP示例里的
IdPInitiatedController完整复制到TestIdPCore项目的Controllers目录下 - 修改Controller里的Initiate方法的参数配置,把目标SP的实体ID、断言消费服务(ACS)地址替换为你要对接的SP的实际配置,代码参考如下:
public IActionResult Initiate() { var relyingParty = new RelyingParty { // 目标SP的实体ID,和SP配置里的EntityId保持一致 EntityId = "https://你的SP域名/Saml2", // 目标SP的ACS地址 AssertionConsumerServiceUrl = "https://你的SP域名/Saml2/AssertionConsumerService" }; var saml2AuthnResponse = new Saml2AuthnResponse(_saml2Configuration) { Destination = relyingParty.AssertionConsumerServiceUrl, Issuer = _saml2Configuration.Issuer, SigningCertificate = _saml2Configuration.SigningCertificate, Subject = new Subject { NameID = new NameID { Value = User.Identity.Name }, SubjectConfirmation = new List<SubjectConfirmation> { new SubjectConfirmation { Method = SubjectConfirmationMethods.Bearer, SubjectConfirmationData = new SubjectConfirmationData { Recipient = relyingParty.AssertionConsumerServiceUrl, NotOnOrAfter = DateTime.UtcNow.AddMinutes(10) } } } }, Conditions = new Conditions { NotBefore = DateTime.UtcNow, NotOnOrAfter = DateTime.UtcNow.AddMinutes(10), AudienceRestrictions = new List<AudienceRestriction> { new AudienceRestriction { Audiences = new List<string> { relyingParty.EntityId } } } } }; saml2AuthnResponse.Status = new Status(Saml2StatusCodes.Success); var binding = new Saml2PostBinding(); binding.SetRelayState("自定义RelayState参数"); return binding.Bind(saml2AuthnResponse).ToActionResult(); }
- 给IdP侧的
IdPInitiated/Initiate路由加授权校验,确保只有已经在IdP完成登录的用户才能访问该接口,避免未授权用户发起SAML响应。
步骤2:SP侧配置
- 不需要额外修改SP的现有SAML配置,只要确保SP的配置里已经添加了当前TestIdPCore作为受信任的IdP,实体ID、签名证书、单登出地址等配置和IdP侧一致即可。
- 如果你需要自定义IdP-initiated流程登录成功后的跳转逻辑,可以修改SP的
AssertionConsumerService方法,判断当前请求是否为IdP-initiated类型(即没有对应AuthnRequest的ID关联),根据需求跳转不同页面。
验证流程
- 先访问IdP的登录页面,完成账号登录
- 访问IdP的
/IdPInitiated/Initiate路由,会自动生成SAML响应通过POST方式提交到目标SP的ACS地址 - SP完成SAML响应校验后自动登录,跳转到默认页面或你自定义的跳转地址
注意:如果需要支持多个SP的IdP-initiated发起,可以给Initiate方法加参数指定目标SP的标识,从IdP的配置里读取对应SP的实体ID和ACS地址,不用硬编码在代码里。
内容的提问来源于stack exchange,提问作者NappyCoder
相关产品推荐
相关产品推荐

