Symfony 2.8项目中LightSAML Bridge Bundle配置及服务实现求助
我之前在Symfony 2.8项目里折腾LightSAML Bridge Bundle的时候,也被这个own_entity_descriptor_provider_service_id的配置搞懵过,给你一步步拆解怎么弄:
这个id对应的服务,本质是给Bridge Bundle提供你的服务实体(SP/IdP)的EntityDescriptor——也就是SAML协议里用来描述服务身份、端点、凭证等核心信息的元数据对象。Bundle需要它来处理SAML请求、响应签名验证、断言消费等关键流程。
首先你需要创建一个类,实现Bundle要求的OwnEntityDescriptorProviderInterface接口,这样Bundle才能正确识别并使用它。
第一步:创建Provider类
// src/Acme/SamlBundle/Provider/OwnEntityDescriptorProvider.php namespace Acme\SamlBundle\Provider; use LightSaml\Model\Metadata\EntityDescriptor; use LightSaml\SymfonyBridgeBundle\Provider\OwnEntityDescriptorProviderInterface; class OwnEntityDescriptorProvider implements OwnEntityDescriptorProviderInterface { private $entityDescriptor; public function __construct() { // 直接在构造函数里构建EntityDescriptor,或者也可以通过依赖注入传入 $this->entityDescriptor = $this->buildEntityDescriptor(); } public function get(): EntityDescriptor { return $this->entityDescriptor; } private function buildEntityDescriptor(): EntityDescriptor { $entityDescriptor = new EntityDescriptor(); // 替换成你的服务实体唯一ID(一般是你的SP/IdP元数据地址) $entityDescriptor->setEntityId('https://your-domain.com/saml/metadata'); // ------------------------------ // 如果你的服务是SP(服务提供者),添加SPSSODescriptor // ------------------------------ $spSsoDescriptor = new \LightSaml\Model\Metadata\SpSsoDescriptor(); $spSsoDescriptor->addProtocolSupportEnumeration(\LightSaml\Model\Metadata\SpSsoDescriptor::PROTOCOL_SAML2); // 添加断言消费者服务(ACS)——IdP会把断言发送到这个地址 $acs = new \LightSaml\Model\Metadata\AssertionConsumerService(); $acs->setLocation('https://your-domain.com/saml/acs'); $acs->setBinding(\LightSaml\Model\Metadata\Binding::SAML2_HTTP_POST); $acs->setIsDefault(true); $spSsoDescriptor->addAssertionConsumerService($acs); // 可选:添加单点注销服务(SLO) $slo = new \LightSaml\Model\Metadata\SingleLogoutService(); $slo->setLocation('https://your-domain.com/saml/slo'); $slo->setBinding(\LightSaml\Model\Metadata\Binding::SAML2_HTTP_REDIRECT); $spSsoDescriptor->addSingleLogoutService($slo); // ------------------------------ // 添加凭证(签名/加密用的证书) // ------------------------------ $keyDescriptor = new \LightSaml\Model\Metadata\KeyDescriptor(); $keyDescriptor->setUse(\LightSaml\Model\Metadata\KeyDescriptor::USE_SIGNING); $x509Data = new \LightSaml\Model\Metadata\X509Data(); $x509Cert = new \LightSaml\Model\Metadata\X509Certificate(); // 替换成你的证书文件路径,Symfony 2.8中%kernel.root_dir%是app/目录 $certContent = file_get_contents(__DIR__.'/../../../../app/Resources/certs/sp.crt'); $x509Cert->setValue($certContent); $x509Data->addX509Certificate($x509Cert); $keyDescriptor->setX509Data($x509Data); $spSsoDescriptor->addKeyDescriptor($keyDescriptor); $entityDescriptor->addItem($spSsoDescriptor); return $entityDescriptor; } }
第二步:在Symfony 2.8中注册这个服务
打开src/Acme/SamlBundle/Resources/config/services.yml(如果没有就新建),把Provider注册为服务:
services: # 自定义的EntityDescriptor Provider服务 acme.saml.own_entity_descriptor_provider: class: Acme\SamlBundle\Provider\OwnEntityDescriptorProvider # 如果你的构造函数有依赖,这里添加arguments
最后在app/config/config.yml里,把Bundle的own.entity_descriptor.id指向你刚注册的服务ID:
light_saml_symfony_bridge: own: entity_descriptor: id: acme.saml.own_entity_descriptor_provider # 补充其他必要配置 store: # 配置IdP元数据存储(比如从文件加载) idp: files: - '%kernel.root_dir%/Resources/saml/idp-metadata.xml' credential: own: # 你的私钥和证书路径 certificate: '%kernel.root_dir%/Resources/certs/sp.crt' key: '%kernel.root_dir%/Resources/certs/sp.key' # 如果私钥有密码,添加这行 # key_passphrase: 'your-key-password'
配置完成后,启动Symfony服务,访问/saml/metadata路由(确保你已经导入了Bridge Bundle的路由,在app/config/routing.yml里添加light_saml_symfony_bridge: resource: "@LightSamlSymfonyBridgeBundle/Resources/config/routing.xml")。如果能正常加载出你的SP元数据,说明配置成功了。
内容的提问来源于stack exchange,提问作者MackDoms

