求基于Apache Camel实现SAML SSO认证的示例代码
Absolutely, many developers have pulled off SAML SSO with Apache Camel! Since Camel doesn’t come with a dedicated SAML component out of the box, the go-to approach is to pair it with Spring Security SAML (or OpenSAML directly) to handle the heavy lifting of the SAML authentication flow, then wire that into your Camel routes.
Below’s a practical example to get you started:
核心依赖(Maven)
First, add these dependencies to your pom.xml to integrate Camel with Spring Security SAML:
<dependencies> <!-- Apache Camel Core --> <dependency> <groupId>org.apache.camel</groupId> <artifactId>camel-core</artifactId> <version>3.20.2</version> <!-- Use your preferred Camel version --> </dependency> <!-- Camel Spring Security Integration --> <dependency> <groupId>org.apache.camel</groupId> <artifactId>camel-spring-security</artifactId> <version>3.20.2</version> </dependency> <!-- Spring Security SAML 2.x --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-saml2-service-provider</artifactId> <version>5.7.8</version> </dependency> <!-- Camel Jetty for HTTP endpoints --> <dependency> <groupId>org.apache.camel</groupId> <artifactId>camel-jetty</artifactId> <version>3.20.2</version> </dependency> </dependencies>
示例实现代码
1. Spring Security SAML 配置
This config sets up the SAML service provider and connects it to your identity provider (IdP):
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.saml2.provider.service.metadata.OpenSamlMetadataResolver; import org.springframework.security.saml2.provider.service.registration.RelyingPartyRegistration; import org.springframework.security.saml2.provider.service.registration.RelyingPartyRegistrationRepository; import org.springframework.security.saml2.provider.service.registration.InMemoryRelyingPartyRegistrationRepository; @EnableWebSecurity @Configuration public class SamlSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/saml/**").permitAll() .anyRequest().authenticated() .and() .saml2Login() .metadataResolver(new OpenSamlMetadataResolver()) .and() .saml2Logout(); } @Bean public RelyingPartyRegistrationRepository relyingPartyRegistrationRepository() { RelyingPartyRegistration registration = RelyingPartyRegistration.withRegistrationId("your-sp-id") .entityId("https://your-service-domain/saml/metadata") .assertionConsumerServiceLocation("https://your-service-domain/login/saml2/sso/your-sp-id") .idpEntityId("https://your-idp-domain/idp/shibboleth") .singleSignOnServiceLocation("https://your-idp-domain/idp/profile/SAML2/Redirect/SSO") .singleLogoutServiceLocation("https://your-idp-domain/idp/profile/SAML2/Redirect/SLO") .idpSigningCertificate("classpath:idp-certificate.crt") .build(); return new InMemoryRelyingPartyRegistrationRepository(registration); } }
2. Camel 受保护路由
This route exposes an HTTP endpoint that requires SAML authentication before processing:
import org.apache.camel.builder.RouteBuilder; import org.springframework.security.core.Authentication; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.stereotype.Component; @Component public class SamlProtectedRoute extends RouteBuilder { @Override public void configure() throws Exception { // Protected API endpoint from("jetty:http://localhost:8080/api/protected") .routeId("saml-protected-api") // Enforce SAML authentication via Spring Security .to("spring-security:authorizationPolicy=#samlAuthPolicy") .process(exchange -> { // Fetch authenticated user details from security context Authentication auth = SecurityContextHolder.getContext().getAuthentication(); String username = auth.getName(); String userRoles = auth.getAuthorities().toString(); exchange.getIn().setBody( String.format("Welcome %s! Your roles: %s\nYou've accessed the SAML-protected Camel route.", username, userRoles) ); }); } }
3. Authorization Policy Bean
Add this bean to define the authorization rules for your route:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.access.prepost.PreAuthorize; import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity; import org.springframework.security.config.annotation.method.configuration.GlobalMethodSecurityConfiguration; @Configuration @EnableGlobalMethodSecurity(prePostEnabled = true) public class AuthPolicyConfig extends GlobalMethodSecurityConfiguration { @Bean(name = "samlAuthPolicy") public PreAuthorize samlAuthorizationPolicy() { // Require users to have at least one valid role (adjust to your needs) return PreAuthorize("@authorizationService.hasValidRole(authentication)"); } }
Key Notes
- Replace placeholder values like
your-sp-id, domain URLs, and certificate paths with your actual IdP and service provider details. - Your IdP should provide metadata or certificate files that you’ll need to place in your classpath.
- For newer Camel versions (4.x+), the integration pattern remains similar—you’ll just need to adjust dependency versions to match Camel 4.x compatibility.
内容的提问来源于stack exchange,提问作者Pradeep Pradeep

