You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解密NameID值并通过NameID获取testuid?SimpleSAMLphp技术咨询

How to Retrieve Plaintext NameID (testuid) Instead of Encrypted/Hash Value

Alright, let's walk through this step by step. First, let's unpack your configuration to understand why you're getting an "encrypted" value right now:

Your IDP's authproc.idp config sets up three NameID generators in sequence:

  • saml:TransientNameID: Creates a one-time, temporary NameID
  • saml:PersistentNameID: Generates a hashed persistent NameID using the eduPersonPrincipalName attribute (this is almost certainly the "encrypted" value you're seeing—persistent NameIDs are hashed, not encrypted, and the hash is irreversible)
  • saml:AttributeNameID: Uses the mail attribute directly as a NameID (in email format)

Plus, your user store (example-userpass) maps testuid:testtest to the uid attribute with value ['testuid'].

Here are two straightforward ways to get the plaintext testuid you need:

Option 1: Grab the uid Directly from Attributes (Easiest!)

Since you're already fetching attributes with $attrs = $as->getAttributes();, you don't even need to mess with the NameID. The testuid value is already in the uid attribute. Just access it directly:

require_once("pathlin"); 
$as = new SimpleSAML_Auth_Simple('default-sp'); 
$attrs = $as->getAttributes();

// Fetch the testuid value
if (isset($attrs['uid']) && !empty($attrs['uid'])) {
    $testuid = $attrs['uid'][0]; // Attributes are arrays, so grab the first element
    echo $testuid; // Will output "testuid" for your test user
}

This is the most direct approach because the uid attribute is already being returned to your SP.

Option 2: Adjust IDP to Return uid as Plaintext NameID

If you specifically need the NameID itself to be testuid, modify your IDP's authproc.idp config to prioritize a NameID generator that uses the uid attribute. Add a saml:AttributeNameID entry at the top of the authproc list (higher numbers run later, so lower numbers take priority):

'authproc.idp' => [
    // Add this to use uid as NameID first
    1 => array(
        'class' => 'saml:AttributeNameID',
        'attribute' => 'uid',
        'Format' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent', // Or your preferred format
    ),
    // Keep existing configs if needed
    2 => array(
        'class' => 'saml:TransientNameID',
    ),
    3 => array(
        'class' => 'saml:PersistentNameID',
        'attribute' => 'eduPersonPrincipalName',
    ),
    4 => array(
        'class' => 'saml:AttributeNameID',
        'attribute' => 'mail',
        'Format' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress',
    ),
],

After this change, when you call $as->getAuthData("saml:sp:NameID")->value, you'll get the plaintext testuid instead of the hashed value.

Key Notes to Keep in Mind

  • The "encrypted" value you're seeing is likely a hash from the PersistentNameID processor, not actual encryption. Hashes can't be reversed to get the original testuid value, so you can't decode it directly—you need to adjust how the NameID is generated instead.
  • Your current PersistentNameID config uses eduPersonPrincipalName, but your test user doesn't have this attribute defined. SimpleSAMLphp might fall back to using uid to generate the hash, but again, that hash is irreversible.
  • If your SP requests a specific NameID format (e.g., email format), the IDP will use the matching generator from your authproc list. Make sure the format you want is prioritized if you go with Option 2.

内容的提问来源于stack exchange,提问作者Antoine Soffray

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:50:43