You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Shibboleth IdP的SAML响应中传递FriendlyName而非URN:OID

解决Shibboleth IdP发送自定义属性名(productid)而非OID的问题

你已经给目标属性设置了FriendlyName,但SAML响应里还是显示OID作为属性键,这通常是因为IdP的属性编码配置或者SP的属性映射规则没匹配上。下面分几种场景给你具体的解决方案:

方案1:让IdP直接发送以productid为名称的属性(推荐,若SP支持)

如果你的服务提供商(SP)兼容非OID格式的属性名称,你可以修改attribute-resolver.xml里的属性编码器,把属性的name字段直接设为productid(符合SAML规范的话,最好搭配自定义命名空间URI):

<resolver:AttributeDefinition id="roomNumber" xsi:type="ad:Simple" sourceAttributeID="roomNumber">
    <resolver:Dependency ref="你的数据源连接器ID"/>
    <!-- 调整SAML2属性编码器的name为productid -->
    <resolver:AttributeEncoder xsi:type="enc:SAML2StringAttributeEncoder"
        name="productid"
        friendlyName="productid"
        attributeNamespace="http://your-org.com/attributes"/>
</resolver:AttributeDefinition>

注:attributeNamespace是可选字段,但加上它更贴合SAML标准,你可以替换成自己组织的命名空间URI。

方案2:配置SP读取FriendlyName而非OID

如果SP支持读取属性的FriendlyName,你无需修改IdP的属性名称,只需调整SP的属性映射规则:

  • 以Shibboleth SP为例,修改attribute-map.xml,添加或更新对应规则,让SP把带有friendlyName="productid"的OID属性映射为本地的productid字段:
<Attribute name="urn:oid:0.9.2342.19200300.100.1.6" friendlyName="productid" id="productid"/>

方案3:检查IdP的属性过滤规则

别忘确认attribute-filter.xml里允许该属性发送到目标SP,且没有限制编码方式:

<afp:AttributeFilterPolicy id="AllowProductidToSP">
    <afp:PolicyRequirementRule xsi:type="basic:Requester" value="你的SP实体ID"/>
    <afp:AttributeRule attributeID="roomNumber">
        <afp:PermitValueRule xsi:type="basic:ANY"/>
    </afp:AttributeRule>
</afp:AttributeFilterPolicy>

最后一步:生效配置

修改完所有配置文件后,一定要重启Shibboleth IdP服务,让新配置生效。之后可以用SAML Tracer这类工具抓包验证,确认属性是否以productid的形式出现在响应中。

内容的提问来源于stack exchange,提问作者Linjo Joson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:22:53