spring-projects / spring-projects/spring-security

Easier SAML metadata configuration via DSL

Open
#15,137 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: saml2 type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Expected Behavior
Some or all of these to be available in some form:

http.saml2Metadata(saml -> saml
    .metadataUrl("/saml/metadata")
    .metadataFilename("my-metadata.xml")
    .entityDescriptorCustomizer(params -> params.getEntityDescriptor().set...)

Current Behavior

OpenSamlMetadataResolver metadataResolver = new OpenSamlMetadataResolver();
metadataResolver.setEntityDescriptorCustomizer(params -> params.getEntityDescriptor().set...);
metadataResolver.setUsePrettyPrint(false);

RequestMatcherMetadataResponseResolver responseResolver =
        new RequestMatcherMetadataResponseResolver(samlRepository, metadataResolver);
responseResolver.setMetadataFilename("my-metadata.xml");
responseResolver.setRequestMatcher(new AntPathRequestMatcher("/saml/metadata"));

http.saml2Metadata(saml -> saml.metadataResponseResolver(responseResolver))

Additional
RelyingPartyRegistrationRepository is not available from http.getSharedObject(). Internally the configurer uses a delegate to provide it to its default metadataResponseResolver, but this is not available to a user-provided one.

Auto-wiring for the entityDescriptorCustomizer would be a nice alternative/addition.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the SAML metadata configuration around OpenSamlMetadataResolver, RequestMatcherMetadataResponseResolver, and the saml2Metadata DSL. Trace how the default metadataResponseResolver receives the RelyingPartyRegistrationRepository and compare that with user-provided resolvers. Done means an agreed DSL design covers the requested metadata settings and repository access, with corresponding tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.