如何在SimpleSamlPHP的authsources.php中为Authnrequest添加samlp:extensions?
Got it, let's break this down. The authsources.php file is just for configuration—you can't directly inject XML extensions there. Instead, you need to use either a custom authentication processing filter or extend the SP class to modify the AuthnRequest before it's sent. Here are two reliable approaches:
Option 1: Use a Custom Authproc Filter
This is the simpler method if you just need to add extensions to the AuthnRequest.
Create the filter file
Make a new file atlib/Auth/Process/CustomAddExtension.phpwith this code:<?php namespace SimpleSAML\Auth\Process; class CustomAddExtension extends \SimpleSAML\Auth\ProcessingFilter { public function process(&$state) { // Skip if there's no active AuthnRequest in the state if (!isset($state['saml:AuthnRequest'])) { return; } $authnRequest = $state['saml:AuthnRequest']; $extensions = $authnRequest->getExtensions(); // Define your custom element and namespace $customNs = 'http://your-custom-namespace.com'; $customElement = \SimpleSAML\XML\DOMDocumentFactory::createElementNS($customNs, 'custom:MyElement'); $customElement->setAttribute('attributeName', 'attributeValue'); $customElement->textContent = 'Example custom content'; // Register the namespace in the AuthnRequest root $authnRequest->getDocument()->documentElement->setAttributeNS( 'http://www.w3.org/2000/xmlns/', 'xmlns:custom', $customNs ); // Add the element to extensions $extensions->appendChild($customElement); } }Enable the filter in authsources.php
Update your SP configuration to include this filter in theauthprocchain (adjust the priority number to fit your existing filters):'your-sp-identifier' => [ 'saml:SP', 'entityID' => 'https://your-sp-domain.com', // ... other SP config options ... 'authproc' => [ // ... your existing authproc steps ... 50 => [ 'class' => 'CustomAddExtension', ], ], ],
Option 2: Extend the SP Class (For More Control)
If you need deeper customization of the AuthnRequest build process, extend the base SP class.
Create the custom SP class
Make a new file atlib/SAML2/SP/CustomSP.php:<?php namespace SimpleSAML\SAML2\SP; use SimpleSAML\SAML2\XML\samlp\AuthnRequest; use SimpleSAML\SAML2\XML\samlp\Extensions; class CustomSP extends \SimpleSAML\SAML2\SP { protected function buildAuthnRequest(array $state): AuthnRequest { // Build the default AuthnRequest first $authnRequest = parent::buildAuthnRequest($state); // Get or create the Extensions section $extensions = $authnRequest->getExtensions(); if ($extensions === null) { $extensions = new Extensions(); $authnRequest->setExtensions($extensions); } // Add your custom content $customNs = 'http://your-custom-namespace.com'; $customElement = \SimpleSAML\XML\DOMDocumentFactory::createElementNS($customNs, 'custom:AdvancedExtension'); $customElement->textContent = 'Custom content for advanced use cases'; $extensions->appendChild($customElement); return $authnRequest; } }Use the custom SP in authsources.php
Replace thesaml:SPclass reference with your custom one:'your-sp-identifier' => [ 'class' => 'SimpleSAML\SAML2\SP\CustomSP', 'entityID' => 'https://your-sp-domain.com', // ... all your existing SP config options ... ],
Critical Notes to Remember
- Namespace Registration: Always declare the XML namespace for your custom elements—otherwise, the IdP might reject the AuthnRequest as invalid.
- Clear Cache: After making changes, delete all files in the
var/cache/directory to ensure SimpleSAMLPHP picks up your new code. - File Permissions: Make sure your custom PHP files have the correct read permissions for your web server (usually
644for files,755for directories).
内容的提问来源于stack exchange,提问作者Ilhicas

