Spring Security 7.0.x中gh-18243修复何时合并及临时版本咨询
Spring Boot 4升级后SAML SSO失效问题解答
修复合并至7.0.x分支的时间
Spring Security 7.0.x作为当前稳定维护分支,gh-18243提及的bug修复会被纳入7.0.x系列的下一个维护版本(预计为7.0.6)。这类关键bug修复的合并通常会在问题确认后的1-2周内完成,后续随维护版本同步发布,你可通过项目的Release Notes或Milestone页面追踪进度。
等待期间的临时恢复方案
在正式维护版本发布前,可通过以下两种方式恢复SSO功能:
- 使用快照版本:配置Spring快照仓库,引入
org.springframework.security:spring-security-saml2-service-provider:7.0.6-SNAPSHOT,该快照版本已包含gh-18243的修复。 - 自定义实现替代:若不想依赖快照版本,可自行实现修复后的
CacheSaml2AuthenticationRequestRepository,核心是修正原实现中缓存键生成的问题,示例代码如下:
public class FixedCacheSaml2AuthenticationRequestRepository implements Saml2AuthenticationRequestRepository<Saml2AuthenticationRequest> { private final Cache<String, Saml2AuthenticationRequest> cache; private final StringKeyGenerator keyGenerator = new WebSessionIdGenerator(); public FixedCacheSaml2AuthenticationRequestRepository(Cache<String, Saml2AuthenticationRequest> cache) { this.cache = cache; } @Override public Saml2AuthenticationRequest loadAuthenticationRequest(HttpServletRequest request) { String key = this.keyGenerator.generateKey(request); return this.cache.get(key, Saml2AuthenticationRequest.class); } @Override public void saveAuthenticationRequest(Saml2AuthenticationRequest authenticationRequest, HttpServletRequest request, HttpServletResponse response) { String key = this.keyGenerator.generateKey(request); this.cache.put(key, authenticationRequest); } @Override public Saml2AuthenticationRequest removeAuthenticationRequest(HttpServletRequest request, HttpServletResponse response) { String key = this.keyGenerator.generateKey(request); return this.cache.evict(key); } }
随后在配置类中替换默认实现:
@Bean public Saml2AuthenticationRequestRepository<Saml2AuthenticationRequest> saml2AuthenticationRequestRepository(CacheManager cacheManager) { Cache<String, Saml2AuthenticationRequest> cache = cacheManager.getCache("saml2AuthenticationRequests"); return new FixedCacheSaml2AuthenticationRequestRepository(cache); }
内容的提问来源于stack exchange,提问作者Vivion Lin
相关产品推荐
相关产品推荐

