gpt4 book ai didi

node.js - Passport-SAML:读取用户信息

转载 作者:行者123 更新时间:2023-12-02 18:36:39 29 4
gpt4 key购买 nike

还是个菜鸟!

我正在构建一个 Node 应用程序,并且我已经设置了各种所需的端点。我的项目的要求之一是使用 SAML 机制进行身份验证。我在我的应用程序中使用 Passport-SAML 进行身份验证。

到目前为止,我已经能够设置和使用 SAML 策略,并且我的应用程序能够调用 idp 入口点,并接收从 Idp 返回的响应。

我无法理解我们如何访问 idp 返回的用户信息,以便我可以使用 SAML 返回的用户信息来创建和维护 session 。

const saml = require('passport-saml');

module.exports = function (passport, config) {

passport.serializeUser(function (user, done) {
done(null, user);
});

passport.deserializeUser(function (user, done) {
done(null, user);
});

var samlStrategyOptions = new saml.Strategy(
{
// URL that goes from the Identity Provider -> Service Provider
callbackUrl: config.passport.saml.callback_url,
// path: config.passport.saml.path,
// URL that goes from the Service Provider -> Identity Provider
entryPoint: config.passport.saml.entryPoint,
issuer: config.passport.saml.issuer,
identifierFormat: null,
// Service Provider private key
decryptionPvk: config.passport.saml.decryptionPvk,
// Service Provider Certificate
privateCert: config.passport.saml.privateCert,
// Identity Provider's public key
cert: config.passport.saml.cert,
validateInResponseTo: false,
disableRequestedAuthnContext: true
},
function (profile, done) {
return done(null,
{
id: profile.uid,
email: profile.email,
displayName: profile.cn,
firstName: profile.givenName,
lastName: profile.sn
});
})


// module.exports.samlStrategyOptions = samlStrategyOptions ;
passport.use(samlStrategyOptions);

};

以下是我的 Express 路线 Controller

router.route('/login')

.get(
passport.authenticate(config.passport.strategy,
{
successRedirect: '/',
failureRedirect: '/login'
})
);

router.route('/login/callback/')

.post(
passport.authenticate(config.passport.strategy,
{
failureRedirect: '/',
failureFlash: true
}),
function (req, res) {

res.redirect('/');
}
);

这是我从 Idp 收到的响应中收到的 SAML 属性片段。

<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">Shubham123</saml:NameID>

最佳答案

我也得到了同样的结果。所以我使用了 body-parser 作为中间件

 // middleware to parse HTTP POST's JSON, buffer, string,zipped or raw and URL encoded data and exposes it on req.body
app.use(bodyParser.json());
// use querystring library to parse x-www-form-urlencoded data for flat data structure (not nested data)
app.use(bodyParser.urlencoded({ extended: false }));

然后你会得到类似的个人资料

{ issuer: '',
sessionIndex: '_x0P5ZeWx-ACSQAulKgVTxSquNsVdac_H',
nameID: 'auth0|5a266569083226773d5d43a9',
nameIDFormat: 'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified',
nameQualifier: undefined,
spNameQualifier: undefined,
'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier': 'auth0|s9ds',
'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress': 'myuser@q.com',
'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name': 'myuser@q.com',
'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn': 'myuser@q.com',
'http://schemas.auth0.com/identities/default/provider': 'auth0',
'http://schemas.auth0.com/identities/default/connection': 'Username-Password-Authentication',
'http://schemas.auth0.com/identities/default/isSocial': 'false',
'http://schemas.auth0.com/email_verified': 'false',
'http://schemas.auth0.com/clientID': 'bZVOM5KQmhyir5xEYhLHGRAQglks2AIp',
'http://schemas.auth0.com/picture': 'https://s.gravatar.com/avatar/e85e57405a82225ff36b5af793ed287c?s=480&r=pg&d=https%3A%2F%2Fcdn.auth0.com%2Favatars%2Fsu.png',
'http://schemas.auth0.com/nickname': 'myuser',
'http://schemas.auth0.com/identities': '[object Object]',
'http://schemas.auth0.com/updated_at': 'Mon Dec 18 2017 12:14:28 GMT+0000 (UTC)',
'http://schemas.auth0.com/created_at': 'Tue Dec 05 2017 09:22:49 GMT+0000 (UTC)',
getAssertionXml: [Function] }

并通过提取数据创建用户,例如

{ id: profile["nameID"], userName: profile["http://schemas.auth0.com/nickname"] }

关于node.js - Passport-SAML:读取用户信息,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/45576447/

29 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com