Upgrade SAML IdP-initiated example to Spring Boot 4.1 with a local Keycloak - #42
Closed
Wictorgirardi wants to merge 8 commits into
Closed
Wictorgirardi wants to merge 8 commits into
Wictorgirardi wants to merge 8 commits into
Conversation
This was referenced Sep 24, 2026
Contributor
Author
|
Combined into #46 with the other Spring Boot example. The changes are the same; only the commit SHAs differ. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #28 for the shared Gradle workflow. The branch includes that commit, and each later commit is one step.
Summary
spring-boot-starter-security-saml2in place of the barespring-security-saml2-service-provider.src/main/resources/credentials/are deleted, along withkeycloak/saml-client.json, which embedded a client private key.scripts/generate-sp-credentials.shcreates the key pair in a gitignoredcredentials/folder. Both old keys stay in the git history, so the README says never to trust them.docker-compose.ymlrunsquay.io/phasetwo/phasetwo-keycloak:26.6on port 8080, without the/authpath, like the tutorial.keycloak/test-realm-export.json, which replaces a 2,200-line export that referenced a real Okta tenant. The new realm has the SAML clientokta-client, the usertest/test, and a disabledokta-brokeridentity provider with placeholder values.-exportsuffix because Keycloak imports a file named<name>-realm.jsonas the realm<name>and refusedtest-realm.json.okta-app→keycloak, and the invalididp-entity-idproperty is removed.SecurityConfigurationaddssaml2Logoutandsaml2Metadata, so the SP publishes its metadata at/saml2/metadata.Saml2AssertionAuthentication, which replaces the deprecatedSaml2AuthenticatedPrincipal.contextLoadstest needed a running Keycloak, so it couldn't pass in CI.saml2-idp-initiated.ymlruns the shared Gradle workflow.Test plan
./gradlew buildpasses without credentials or Keycloak (5 tests), with the Java 21 toolchain.docker compose up -d --waitimports the realm, and the admin API shows the expected client, mappers, identity provider and user.InResponseTo) and signed, with Destination = ACS and Audience = SP entity ID.test,email,firstNameandlastName.InResponseTo).LogoutRequestgets a signed successLogoutResponse.invalid_signature.Docs drift
blog/2025-02-25-saml-idp-initiated-flow.mdx:/auth. Point it to the example'sdocker compose up -d --waitinstead. Hosted Phase Two URLs include/auth.okta-brokernow clashes with the disabled placeholder in the realm. Readers should edit that one instead (entity ID, SSO URL, certificate, then enable it) or delete it first../scripts/generate-sp-credentials.shand start Keycloak. The SP serves its metadata at/saml2/metadata.saml-client.json, which is gone, since the client now comes with the realm.http://localhost:8081/saml2/metadata, which also turns "Client signature required" on.okta-client.http://localhost:8080/realms/test-realm/protocol/saml/clients/okta-client, usertest/test.okta-broker,okta-client,/login/saml2/sso,/saml2/metadata, the example link and the client screenshots.#service-provider-initated-flowand#identity-provider-initated-flow(L26–27) are misspelled.ACS", "a OIDC".