Add properties for SAML relying party single logout
Closes gh-30128 Co-authored-by: Madhura Bhave <bhavem@vmware.com>
This commit is contained in:
committed by
Madhura Bhave
parent
179e37279d
commit
7d459a13c2
@@ -262,6 +262,10 @@ You can register multiple relying parties under the `spring.security.saml2.relyi
|
||||
credentials:
|
||||
- private-key-location: "path-to-private-key"
|
||||
certificate-location: "path-to-certificate"
|
||||
singlelogout:
|
||||
url: "https://myapp/logout/saml2/slo"
|
||||
reponse-url: "https://remoteidp2.slo.url"
|
||||
binding: "POST"
|
||||
assertingparty:
|
||||
verification:
|
||||
credentials:
|
||||
@@ -284,4 +288,14 @@ You can register multiple relying parties under the `spring.security.saml2.relyi
|
||||
- certificate-location: "path-to-other-verification-cert"
|
||||
entity-id: "remote-idp-entity-id2"
|
||||
sso-url: "https://remoteidp2.sso.url"
|
||||
singlelogout:
|
||||
url: "https://remoteidp2.slo.url"
|
||||
reponse-url: "https://myapp/logout/saml2/slo"
|
||||
binding: "POST"
|
||||
----
|
||||
|
||||
For SAML2 logout, by default, Spring Security's `Saml2LogoutRequestFilter` and `Saml2LogoutResponseFilter` only process URLs matching `/logout/saml2/slo`.
|
||||
If you want to customize the `url` to which AP-initiated logout requests get sent to or the `response-url` to which an AP sends logout responses to, to use a different pattern, you need to provide configuration to process that custom pattern.
|
||||
For example, for servlet applications, you can add your own `SecurityFilterChain` that resembles the following:
|
||||
|
||||
include::code:MySamlRelyingPartyConfiguration[]
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* https://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.boot.docs.web.security.saml2.relyingparty;
|
||||
|
||||
import org.springframework.context.annotation.Bean;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
|
||||
import org.springframework.security.web.SecurityFilterChain;
|
||||
|
||||
@Configuration(proxyBeanMethods = false)
|
||||
public class MySamlRelyingPartyConfiguration {
|
||||
|
||||
@Bean
|
||||
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
|
||||
http.authorizeRequests().anyRequest().authenticated();
|
||||
http.saml2Login();
|
||||
http.saml2Logout((saml2) -> saml2.logoutRequest((request) -> request.logoutUrl("/SLOService.saml2"))
|
||||
.logoutResponse((response) -> response.logoutUrl("/SLOService.saml2")));
|
||||
return http.build();
|
||||
}
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user