You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在SimpleSamlPHP的authsources.php中为Authnrequest添加samlp:extensions?

How to Add Custom Content to samlp:Extensions in AuthnRequest (SimpleSAMLPHP)

Got it, let's break this down. The authsources.php file is just for configuration—you can't directly inject XML extensions there. Instead, you need to use either a custom authentication processing filter or extend the SP class to modify the AuthnRequest before it's sent. Here are two reliable approaches:

Option 1: Use a Custom Authproc Filter

This is the simpler method if you just need to add extensions to the AuthnRequest.

  1. Create the filter file
    Make a new file at lib/Auth/Process/CustomAddExtension.php with this code:

    <?php
    namespace SimpleSAML\Auth\Process;
    
    class CustomAddExtension extends \SimpleSAML\Auth\ProcessingFilter
    {
        public function process(&$state)
        {
            // Skip if there's no active AuthnRequest in the state
            if (!isset($state['saml:AuthnRequest'])) {
                return;
            }
    
            $authnRequest = $state['saml:AuthnRequest'];
            $extensions = $authnRequest->getExtensions();
    
            // Define your custom element and namespace
            $customNs = 'http://your-custom-namespace.com';
            $customElement = \SimpleSAML\XML\DOMDocumentFactory::createElementNS($customNs, 'custom:MyElement');
            $customElement->setAttribute('attributeName', 'attributeValue');
            $customElement->textContent = 'Example custom content';
    
            // Register the namespace in the AuthnRequest root
            $authnRequest->getDocument()->documentElement->setAttributeNS(
                'http://www.w3.org/2000/xmlns/',
                'xmlns:custom',
                $customNs
            );
    
            // Add the element to extensions
            $extensions->appendChild($customElement);
        }
    }
    
  2. Enable the filter in authsources.php
    Update your SP configuration to include this filter in the authproc chain (adjust the priority number to fit your existing filters):

    'your-sp-identifier' => [
        'saml:SP',
        'entityID' => 'https://your-sp-domain.com',
        // ... other SP config options ...
        'authproc' => [
            // ... your existing authproc steps ...
            50 => [
                'class' => 'CustomAddExtension',
            ],
        ],
    ],
    

Option 2: Extend the SP Class (For More Control)

If you need deeper customization of the AuthnRequest build process, extend the base SP class.

  1. Create the custom SP class
    Make a new file at lib/SAML2/SP/CustomSP.php:

    <?php
    namespace SimpleSAML\SAML2\SP;
    
    use SimpleSAML\SAML2\XML\samlp\AuthnRequest;
    use SimpleSAML\SAML2\XML\samlp\Extensions;
    
    class CustomSP extends \SimpleSAML\SAML2\SP
    {
        protected function buildAuthnRequest(array $state): AuthnRequest
        {
            // Build the default AuthnRequest first
            $authnRequest = parent::buildAuthnRequest($state);
    
            // Get or create the Extensions section
            $extensions = $authnRequest->getExtensions();
            if ($extensions === null) {
                $extensions = new Extensions();
                $authnRequest->setExtensions($extensions);
            }
    
            // Add your custom content
            $customNs = 'http://your-custom-namespace.com';
            $customElement = \SimpleSAML\XML\DOMDocumentFactory::createElementNS($customNs, 'custom:AdvancedExtension');
            $customElement->textContent = 'Custom content for advanced use cases';
    
            $extensions->appendChild($customElement);
    
            return $authnRequest;
        }
    }
    
  2. Use the custom SP in authsources.php
    Replace the saml:SP class reference with your custom one:

    'your-sp-identifier' => [
        'class' => 'SimpleSAML\SAML2\SP\CustomSP',
        'entityID' => 'https://your-sp-domain.com',
        // ... all your existing SP config options ...
    ],
    

Critical Notes to Remember

  • Namespace Registration: Always declare the XML namespace for your custom elements—otherwise, the IdP might reject the AuthnRequest as invalid.
  • Clear Cache: After making changes, delete all files in the var/cache/ directory to ensure SimpleSAMLPHP picks up your new code.
  • File Permissions: Make sure your custom PHP files have the correct read permissions for your web server (usually 644 for files, 755 for directories).

内容的提问来源于stack exchange,提问作者Ilhicas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 09:18:03