如何在SimpleSAMLphp IdP中用属性值替换NameID值?
Fix: Set Email-Format NameID in kristophjunge/test-saml-idp for SP-Initiated Flow
Looks like you're just one tiny typo away from getting this working! The core issue in your _saml20-sp-remote.php is a misspelled class name in the authproc filter, which is preventing the NameID from being populated with your user's email attribute.
Corrected _saml20-sp-remote.php Configuration
Here's the fixed version of your SP remote metadata file:
<?php /** * SAML 2.0 remote SP metadata for SimpleSAMLphp. * * See: https://simplesamlphp.org/docs/stable/simplesamlphp-reference-sp-remote */ $metadata[getenv('SIMPLESAMLPHP_SP_ENTITY_ID')] = array( 'AssertionConsumerService' => getenv('SIMPLESAMLPHP_SP_ASSERTION_CONSUMER_SERVICE'), 'SingleLogoutService' => getenv('SIMPLESAMLPHP_SP_SINGLE_LOGOUT_SERVICE'), 'authproc.idp' => array( /* Filter to create a NameID using the email attribute in emailAddress format */ 3 => array( 'class' => 'saml:AttributeNameID', // Fixed typo here: "Attribute" not "Atrribute" 'attribute' => 'email', 'Format' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress', ), ), /* Explicitly set the default NameID format to match our filter */ 'NameIDFormat' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress', );
Key Fixes Explained
- Typo Correction: You had
saml:AtrributeNameID(missing the second 't' in "Attribute"). This meant the IdP couldn't load the correct NameID generator filter, so it fell back to using a random temporary ID. - Aligned NameIDFormat: I updated the top-level
NameIDFormatto match the format specified in the authproc filter (emailAddress), which ensures consistency with G Suite's behavior.
Steps to Apply the Fix
- Update your
_saml20-sp-remote.phpfile with the corrected code above. - Restart your Docker container to apply the changes:
docker restart testsamlidp_idp - Test the SP-initiated flow again. You should now see the user's email (e.g.,
user1@example.com) as the NameID in the SAML response, just like G Suite provides.
Verification Tip
To confirm the fix works, you can use a SAML tracer tool (like the browser extension) to inspect the SAML response from the IdP. Look for the <saml:NameID> element—it should contain the user's email address with the Format attribute set to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.
内容的提问来源于stack exchange,提问作者Simeon Leyzerzon
相关产品推荐
相关产品推荐

