You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过cURL命令无浏览器认证SimpleSAML网站?

Authenticating to a SimpleSAML-Protected Site with cURL (No Browser)

Got it, let's walk through finishing this flow since you've already made progress hitting the IDP login page and submitting credentials. Here's how to handle the redirect to your OAM SSO page and complete the authentication:

Step 1: Preserve Session Cookies

SimpleSAML relies heavily on session cookies, so start by saving the initial session from the IDP login page:

curl -c cookies.txt "https://idp.mycompany.com/simplesaml/module.php/core/login.php?"

The -c flag saves cookies to a file so subsequent requests can reuse the session.

Step 2: Submit Credentials with Exact Form Parameters

When you submit your login via Chrome, check the Form Data tab in DevTools to capture all parameters sent (not just username/password—there are usually hidden fields like RelayState, SAMLAuthnRequest, or a CSRF token). Use these in your POST request, and make sure to load/update cookies:

# Replace placeholders with actual values from DevTools
curl -b cookies.txt -c cookies.txt \
  -d "username=your_actual_username" \
  -d "password=your_actual_password" \
  -d "RelayState=the_relay_state_from_devtools" \
  -d "SAMLAuthnRequest=the_saml_request_from_devtools" \
  "https://idp.mycompany.com/simplesaml/module.php/core/login.php?"
  • -b: Loads existing cookies from the file
  • -c: Updates the cookie file with new session data from the response

Step 3: Follow the Redirect to OAM

After submitting credentials, the IDP will send a 3xx redirect to your OAM SSO page. Use -L to tell cURL to automatically follow redirects, and keep using your cookie file:

curl -L -b cookies.txt -c cookies.txt "https://login-page.mycompany.com/oam/server..."

If the OAM page requires an additional form submission (like another set of credentials or a consent prompt), repeat the process: capture the form parameters from DevTools and send a POST with -d.

Step 4: Verify Authentication

Once you've worked through all redirects, test access to a protected page using your saved cookies:

curl -b cookies.txt "https://your-target-app.mycompany.com/protected-resource"

If you get the expected content instead of a redirect to login, you're authenticated!

Key Tips to Avoid Pitfalls

  • Match Browser User-Agent: Some servers block non-browser User-Agents. Add this flag to mimic Chrome:
    -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
    
  • Extract CSRF Tokens Dynamically: If the login page has a CSRF token (look for an input with name="csrf_token" or similar), don't hardcode it—extract it from the initial page response:
    CSRF_TOKEN=$(curl -c cookies.txt "https://idp.mycompany.com/simplesaml/module.php/core/login.php?" | grep -oP 'name="csrf_token" value="\K[^"]+')
    # Then add -d "csrf_token=$CSRF_TOKEN" to your POST request
    
  • Skip Certificate Checks (Only for Testing): If your company uses self-signed SSL certificates, add -k to bypass validation (never use this in production).

内容的提问来源于stack exchange,提问作者SergioLeone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:47:00