You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非Maven架构Java Tomcat应用集成SAML SSO最简方案咨询

Most Straightforward SAML SSO Solution for Your Non-Maven Java App

Hey there! Since you already have your IDP and metadata.xml ready, adding SAML SSO to your NetBeans/Tomcat/Apache-based Java app (no Maven required) is totally doable with a straightforward, manual approach. Here's how to tackle it step by step:

1. Choose a SAML Library That Works Without Maven

Skip heavy, Maven-tied frameworks—go with OneLogin's java-saml library. It’s lightweight, well-documented, and you can download pre-compiled JARs (plus all required dependencies) directly from its repository.

  • Grab the core java-saml JAR and its dependencies (like OpenSAML components, commons-logging, etc.)
  • Drop all these JARs into your app’s WEB-INF/lib folder (in NetBeans, just drag them into the project’s Libraries section to add them to the classpath)

2. Configure Your Service Provider (SP) Settings

Create a configuration file (or a Java constants class) to link your app with the IDP:

  • Point to your existing metadata.xml file (place it in WEB-INF/classes so it’s accessible via the classpath)
  • Define your SP’s entity ID (e.g., https://your-app-domain.com/saml/sp)
  • Set the Assertion Consumer Service (ACS) URL: this is where the IDP will send the SAML response (e.g., https://your-app-domain.com/saml/acs)
  • Specify trust settings (e.g., accept the IDP’s certificate from the metadata, or hardcode it if needed)

Here’s a quick snippet of a config class:

public class SamlConfig {
    public static final String IDP_METADATA_PATH = "/WEB-INF/classes/metadata.xml";
    public static final String SP_ENTITY_ID = "https://your-app-domain.com/saml/sp";
    public static final String ACS_URL = "https://your-app-domain.com/saml/acs";
    // Add other settings like signing/encryption flags if needed
}

3. Add SAML Endpoint Servlets

Tomcat runs on servlets, so you’ll need two key servlets to handle the SAML flow:

a. SSO Initiation Servlet (SamlLoginServlet)

This servlet triggers the redirect to your IDP’s login page by generating a SAML AuthnRequest:

public class SamlLoginServlet extends HttpServlet {
    protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        // Use java-saml library to load IDP metadata
        // Generate AuthnRequest and encode it
        String encodedAuthnRequest = // ... generate via library
        String idpSsoUrl = // Extract from IDP metadata
        // Redirect the user to the IDP's SSO URL
        response.sendRedirect(idpSsoUrl + "?SAMLRequest=" + encodedAuthnRequest);
    }
}

b. Assertion Consumer Service (ACS) Servlet (SamlAcsServlet)

This servlet handles the POST response from the IDP, validates the SAML assertion, and logs the user into your app:

public class SamlAcsServlet extends HttpServlet {
    protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        // Extract SAMLResponse from the POST request
        String samlResponse = request.getParameter("SAMLResponse");
        // Use java-saml to validate the response (check signature, issuer, expiration)
        // Parse the assertion to get user attributes (e.g., email, user ID)
        Map<String, String> userAttributes = // ... parse from assertion
        // Create a session for the user in your app
        request.getSession().setAttribute("loggedInUser", userAttributes);
        // Redirect to your app's home page
        response.sendRedirect("/home");
    }
}

Don’t forget to register these servlets in your web.xml file:

<servlet>
    <servlet-name>SamlLoginServlet</servlet-name>
    <servlet-class>com.yourpackage.SamlLoginServlet</servlet-class>
</servlet>
<servlet-mapping>
    <servlet-name>SamlLoginServlet</servlet-name>
    <url-pattern>/saml/login</url-pattern>
</servlet-mapping>

<servlet>
    <servlet-name>SamlAcsServlet</servlet-name>
    <servlet-class>com.yourpackage.SamlAcsServlet</servlet-class>
</servlet>
<servlet-mapping>
    <servlet-name>SamlAcsServlet</servlet-name>
    <url-pattern>/saml/acs</url-pattern>
</servlet-mapping>

4. Integrate With Your App’s Existing Auth Flow

  • Map the user attributes from the SAML assertion to your app’s user database (e.g., check if the email from the assertion exists in your system)
  • Update your app’s login links to point to /saml/login instead of your old login page
  • Add checks in protected routes to ensure the user has a valid SAML-based session

5. Configure Apache Reverse Proxy (If Needed)

Since your app sits behind Apache:

  • Set up SSL on Apache (SAML requires HTTPS for production)
  • Configure Apache to forward requests to /saml/* to your Tomcat instance (use mod_proxy and mod_proxy_http)
  • Make sure the ACS URL you defined matches the public URL that Apache exposes

6. Test the Flow

  1. Visit your app’s login link (/saml/login)—you should be redirected to the IDP’s login page
  2. Log in with valid IDP credentials
  3. Verify you’re redirected back to your app’s home page and the user session is active
  4. Test logout (if you add SLO support) to ensure the session is invalidated both in your app and the IDP

内容的提问来源于stack exchange,提问作者Gilbert

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 08:14:23