Redirect to IdP Automatically with Spring SAML

Started working with SAML recently and faced all the problems, most of which I developed. However, the one I still don't have is how to turn off discovery, so Spring will automatically redirect the IdP (I only have one, and also its default) when accessing any protected resource. I see in the Springs docs that you can easily turn off detection, however the docs seem to be missing examples and / or details, so I'm not entirely sure how to do this.

So far, I've tried setting idpSelectionPath to empty and also using includeDiscoveryExtension and idpDiscoveryEnabled to set it to false. Using a direct url (context / saml / login? Idp = IDP) does work, but is not an option as my requirement for any secure url to automatically redirect to an IdP if the user is not signed in.

Below is a working version of my securityContext.xml file, as some of the changes I made (like removing all detection options) caused an infinite loop browser error. Any help is appreciated. Thank!

<?xml version="1.0" encoding="UTF-8" ?>
<beans xmlns=""

<!-- Enable auto-wiring -->
<context:component-scan base-package=""/>

<!-- Unsecured pages -->
<security:http security="none" pattern="/saml/web/**"/>
<security:http security="none" pattern="/logout.jsp"/>
<security:http security="none" pattern="/favicon.ico"/>

<!-- Secured pages -->
<security:http entry-point-ref="samlEntryPoint">
    <security:intercept-url pattern="/**" access="IS_AUTHENTICATED_FULLY"/>
    <security:custom-filter before="FIRST" ref="metadataGeneratorFilter"/>
    <security:custom-filter after="BASIC_AUTH_FILTER" ref="samlFilter"/>

<bean id="samlFilter" class="">
    <security:filter-chain-map request-matcher="ant">
        <security:filter-chain pattern="/saml/login/**" filters="samlEntryPoint"/>
        <security:filter-chain pattern="/saml/logout/**" filters="samlLogoutFilter"/>
        <security:filter-chain pattern="/saml/metadata/**" filters="metadataDisplayFilter"/>
        <security:filter-chain pattern="/saml/SSO/**" filters="samlWebSSOProcessingFilter"/>
        <security:filter-chain pattern="/saml/SSOHoK/**" filters="samlWebSSOHoKProcessingFilter"/>
        <security:filter-chain pattern="/saml/SingleLogout/**" filters="samlLogoutProcessingFilter"/>
        <security:filter-chain pattern="/saml/discovery/**" filters="samlIDPDiscovery"/>

<!-- Handler deciding where to redirect user after successful login -->
<bean id="successRedirectHandler"
    <property name="defaultTargetUrl" value="/"/>
Use the following for interpreting RelayState coming from unsolicited response as redirect URL:
<bean id="successRedirectHandler" class="">
   <property name="defaultTargetUrl" value="/" />

<!-- Handler for successful logout -->
<bean id="successLogoutHandler" class="">
    <property name="defaultTargetUrl" value="/logout.jsp"/>

<!-- Register authentication manager with SAML provider -->
<security:authentication-manager alias="authenticationManager">
    <security:authentication-provider ref="samlAuthenticationProvider"/>

<!-- Logger for SAML messages and events -->
<bean id="samlLogger" class=""/>

<!-- Central storage of cryptographic keys -->
<bean id="keyManager" class="">
    <constructor-arg value="classpath:security/samlKeystore.jks"/>
    <constructor-arg type="java.lang.String" value="nalle123"/>
            <entry key="apollo" value="nalle123"/>
    <constructor-arg type="java.lang.String" value="apollo"/>

<!-- Entry point to initialize authentication, default values taken from properties file -->
<bean id="samlEntryPoint" class="">
    <property name="defaultProfileOptions">
        <bean class="">
            <property name="includeScoping" value="false"/>

<!-- IDP Discovery Service -->
<bean id="samlIDPDiscovery" class="">
    <property name="idpSelectionPath" value="/WEB-INF/security/idpSelection.jsp"/>

<!-- Filter automatically generates default SP metadata -->



<!-- The filter is waiting for connections on URL suffixed with filterSuffix and presents SP metadata there -->
<bean id="metadataDisplayFilter" class=""/>

<!-- IDP Metadata configuration - paths to metadata of IDPs in circle of trust is here -->
<!-- Do no forget to call iniitalize method on providers -->
<bean id="metadata" class="">
        <bean class="">
    <bean class="org.opensaml.saml2.metadata.provider.FilesystemMetadataProvider">
            <value type="">C:/SAMLIdP-00D1a000000KR5C.xml</value>
        <property name="parserPool" ref="parserPool"/>
    <bean class=""/>
<property name="defaultIDP" value=""/>

<!-- SAML Authentication Provider responsible for validating of received SAML messages -->
<bean id="samlAuthenticationProvider" class="">
    <!-- OPTIONAL property: can be used to store/load user data after login -->
    <property name="userDetails" ref="bean" />

<!-- Provider of default SAML Context -->
<bean id="contextProvider" class=""/>

<!-- Processing filter for WebSSO profile messages -->
<bean id="samlWebSSOProcessingFilter" class="">
    <property name="authenticationManager" ref="authenticationManager"/>
    <property name="authenticationSuccessHandler" ref="successRedirectHandler"/>

<!-- Processing filter for WebSSO Holder-of-Key profile -->
<bean id="samlWebSSOHoKProcessingFilter" class="">
    <property name="authenticationManager" ref="authenticationManager"/>
    <property name="authenticationSuccessHandler" ref="successRedirectHandler"/>

<!-- Logout handler terminating local session -->
<bean id="logoutHandler"
    <property name="invalidateHttpSession" value="false"/>

<!-- Override default logout processing filter with the one processing SAML messages -->
<bean id="samlLogoutFilter" class="">
    <constructor-arg ref="successLogoutHandler"/>
    <constructor-arg ref="logoutHandler"/>
    <constructor-arg ref="logoutHandler"/>

<!-- Filter processing incoming logout messages -->
<!-- First argument determines URL user will be redirected to after successful global logout -->
<bean id="samlLogoutProcessingFilter" class="">
    <constructor-arg ref="successLogoutHandler"/>
    <constructor-arg ref="logoutHandler"/>

<!-- Class loading incoming SAML messages from httpRequest stream -->
<bean id="processor" class="">
            <ref bean="redirectBinding"/>
            <ref bean="postBinding"/>
            <ref bean="artifactBinding"/>
            <ref bean="soapBinding"/>
            <ref bean="paosBinding"/>

<!-- SAML 2.0 WebSSO Assertion Consumer -->
<bean id="webSSOprofileConsumer" class=""/>

<!-- SAML 2.0 Holder-of-Key WebSSO Assertion Consumer -->
<bean id="hokWebSSOprofileConsumer" class=""/>

<!-- SAML 2.0 Web SSO profile -->
<bean id="webSSOprofile" class=""/>

<!-- SAML 2.0 Holder-of-Key Web SSO profile -->
<bean id="hokWebSSOProfile" class=""/>

<!-- SAML 2.0 ECP profile -->
<bean id="ecpprofile" class=""/>

<!-- SAML 2.0 Logout Profile -->
<bean id="logoutprofile" class=""/>

<!-- Bindings, encoders and decoders used for creating and parsing messages -->
<bean id="postBinding" class="">
    <constructor-arg ref="parserPool"/>
    <constructor-arg ref="velocityEngine"/>

<bean id="redirectBinding" class="">
    <constructor-arg ref="parserPool"/>

<bean id="artifactBinding" class="">
    <constructor-arg ref="parserPool"/>
    <constructor-arg ref="velocityEngine"/>
        <bean class="">
                <bean class="org.apache.commons.httpclient.HttpClient"/>
            <property name="processor">
                <bean id="soapProcessor" class="">
                    <constructor-arg ref="soapBinding"/>

<bean id="soapBinding" class="">
    <constructor-arg ref="parserPool"/>

<bean id="paosBinding" class="">
    <constructor-arg ref="parserPool"/>

<!-- Initialization of OpenSAML library-->
<bean class=""/>

<!-- Initialization of the velocity engine -->
<bean id="velocityEngine" class="" factory-method="getEngine"/>

<!-- XML parser pool needed for OpenSAML parsing -->
<bean id="parserPool" class="org.opensaml.xml.parse.StaticBasicParserPool" scope="singleton" init-method="initialize"/>
<bean id="parserPoolHolder" class="" scope="singleton"/>



source to share

1 answer

Setting the idpDiscoveryEnabled property to false in the MetadataGeneratorFilter worked for me. Something like:

    <bean id="metadataGeneratorFilter" class="">
            <bean class="">
                <property name="extendedMetadata">
                    <bean class="">
                        <property name="idpDiscoveryEnabled" value="false"/>




All Articles