非Maven架构Java Tomcat应用集成SAML SSO最简方案咨询
Hey there! Since you already have your IDP and metadata.xml ready, adding SAML SSO to your NetBeans/Tomcat/Apache-based Java app (no Maven required) is totally doable with a straightforward, manual approach. Here's how to tackle it step by step:
1. Choose a SAML Library That Works Without Maven
Skip heavy, Maven-tied frameworks—go with OneLogin's java-saml library. It’s lightweight, well-documented, and you can download pre-compiled JARs (plus all required dependencies) directly from its repository.
- Grab the core
java-samlJAR and its dependencies (like OpenSAML components, commons-logging, etc.) - Drop all these JARs into your app’s
WEB-INF/libfolder (in NetBeans, just drag them into the project’s Libraries section to add them to the classpath)
2. Configure Your Service Provider (SP) Settings
Create a configuration file (or a Java constants class) to link your app with the IDP:
- Point to your existing
metadata.xmlfile (place it inWEB-INF/classesso it’s accessible via the classpath) - Define your SP’s entity ID (e.g.,
https://your-app-domain.com/saml/sp) - Set the Assertion Consumer Service (ACS) URL: this is where the IDP will send the SAML response (e.g.,
https://your-app-domain.com/saml/acs) - Specify trust settings (e.g., accept the IDP’s certificate from the metadata, or hardcode it if needed)
Here’s a quick snippet of a config class:
public class SamlConfig { public static final String IDP_METADATA_PATH = "/WEB-INF/classes/metadata.xml"; public static final String SP_ENTITY_ID = "https://your-app-domain.com/saml/sp"; public static final String ACS_URL = "https://your-app-domain.com/saml/acs"; // Add other settings like signing/encryption flags if needed }
3. Add SAML Endpoint Servlets
Tomcat runs on servlets, so you’ll need two key servlets to handle the SAML flow:
a. SSO Initiation Servlet (SamlLoginServlet)
This servlet triggers the redirect to your IDP’s login page by generating a SAML AuthnRequest:
public class SamlLoginServlet extends HttpServlet { protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { // Use java-saml library to load IDP metadata // Generate AuthnRequest and encode it String encodedAuthnRequest = // ... generate via library String idpSsoUrl = // Extract from IDP metadata // Redirect the user to the IDP's SSO URL response.sendRedirect(idpSsoUrl + "?SAMLRequest=" + encodedAuthnRequest); } }
b. Assertion Consumer Service (ACS) Servlet (SamlAcsServlet)
This servlet handles the POST response from the IDP, validates the SAML assertion, and logs the user into your app:
public class SamlAcsServlet extends HttpServlet { protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { // Extract SAMLResponse from the POST request String samlResponse = request.getParameter("SAMLResponse"); // Use java-saml to validate the response (check signature, issuer, expiration) // Parse the assertion to get user attributes (e.g., email, user ID) Map<String, String> userAttributes = // ... parse from assertion // Create a session for the user in your app request.getSession().setAttribute("loggedInUser", userAttributes); // Redirect to your app's home page response.sendRedirect("/home"); } }
Don’t forget to register these servlets in your web.xml file:
<servlet> <servlet-name>SamlLoginServlet</servlet-name> <servlet-class>com.yourpackage.SamlLoginServlet</servlet-class> </servlet> <servlet-mapping> <servlet-name>SamlLoginServlet</servlet-name> <url-pattern>/saml/login</url-pattern> </servlet-mapping> <servlet> <servlet-name>SamlAcsServlet</servlet-name> <servlet-class>com.yourpackage.SamlAcsServlet</servlet-class> </servlet> <servlet-mapping> <servlet-name>SamlAcsServlet</servlet-name> <url-pattern>/saml/acs</url-pattern> </servlet-mapping>
4. Integrate With Your App’s Existing Auth Flow
- Map the user attributes from the SAML assertion to your app’s user database (e.g., check if the email from the assertion exists in your system)
- Update your app’s login links to point to
/saml/logininstead of your old login page - Add checks in protected routes to ensure the user has a valid SAML-based session
5. Configure Apache Reverse Proxy (If Needed)
Since your app sits behind Apache:
- Set up SSL on Apache (SAML requires HTTPS for production)
- Configure Apache to forward requests to
/saml/*to your Tomcat instance (usemod_proxyandmod_proxy_http) - Make sure the ACS URL you defined matches the public URL that Apache exposes
6. Test the Flow
- Visit your app’s login link (
/saml/login)—you should be redirected to the IDP’s login page - Log in with valid IDP credentials
- Verify you’re redirected back to your app’s home page and the user session is active
- Test logout (if you add SLO support) to ensure the session is invalidated both in your app and the IDP
内容的提问来源于stack exchange,提问作者Gilbert

