You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在SimpleSAMLphp IdP中用属性值替换NameID值?

Fix: Set Email-Format NameID in kristophjunge/test-saml-idp for SP-Initiated Flow

Looks like you're just one tiny typo away from getting this working! The core issue in your _saml20-sp-remote.php is a misspelled class name in the authproc filter, which is preventing the NameID from being populated with your user's email attribute.

Corrected _saml20-sp-remote.php Configuration

Here's the fixed version of your SP remote metadata file:

<?php
/**
 * SAML 2.0 remote SP metadata for SimpleSAMLphp.
 *
 * See: https://simplesamlphp.org/docs/stable/simplesamlphp-reference-sp-remote
 */
$metadata[getenv('SIMPLESAMLPHP_SP_ENTITY_ID')] = array(
    'AssertionConsumerService' => getenv('SIMPLESAMLPHP_SP_ASSERTION_CONSUMER_SERVICE'),
    'SingleLogoutService' => getenv('SIMPLESAMLPHP_SP_SINGLE_LOGOUT_SERVICE'),
    'authproc.idp' => array(
        /* Filter to create a NameID using the email attribute in emailAddress format */
        3 => array(
            'class' => 'saml:AttributeNameID', // Fixed typo here: "Attribute" not "Atrribute"
            'attribute' => 'email',
            'Format' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress',
        ),
    ),
    /* Explicitly set the default NameID format to match our filter */
    'NameIDFormat' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress',
);

Key Fixes Explained

  1. Typo Correction: You had saml:AtrributeNameID (missing the second 't' in "Attribute"). This meant the IdP couldn't load the correct NameID generator filter, so it fell back to using a random temporary ID.
  2. Aligned NameIDFormat: I updated the top-level NameIDFormat to match the format specified in the authproc filter (emailAddress), which ensures consistency with G Suite's behavior.

Steps to Apply the Fix

  1. Update your _saml20-sp-remote.php file with the corrected code above.
  2. Restart your Docker container to apply the changes:
    docker restart testsamlidp_idp
    
  3. Test the SP-initiated flow again. You should now see the user's email (e.g., user1@example.com) as the NameID in the SAML response, just like G Suite provides.

Verification Tip

To confirm the fix works, you can use a SAML tracer tool (like the browser extension) to inspect the SAML response from the IdP. Look for the <saml:NameID> element—it should contain the user's email address with the Format attribute set to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.

内容的提问来源于stack exchange,提问作者Simeon Leyzerzon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:49:11