Requirements
SAML needsConfig.Organizations to be set, and theauth.New returns ErrSAMLRequiresOrganizations otherwise. It also needs a storage backend with organization support: memory, Postgres or MySQL. SQLite does not support organizations, SAML, SCIM or RBAC.
You need an RSA keypair for the SP, PEM encoded. The certificate and key sign outbound AuthnRequests and identify the SP in its metadata.
Configure
AuthnRequestTTL defaults to 10 minutes and ClockSkew to 30 seconds. Some IdPs with drifting clocks need 60 seconds. AllowedRelayStates lists extra post-login destinations (exact absolute URLs, or paths ending in *). Same-site paths and PostLoginRedirect are always accepted; anything else falls back to PostLoginRedirect.
Create a connection
Connections can be created over HTTP (below) or from Go:AttributeMap tells the library which assertion attributes carry the email, name and groups. The default map uses the claim URIs that Microsoft, Okta and OneLogin emit. An assertion with no mapped email is rejected (ErrSAMLMissingEmail). Related methods: UpdateSAMLConnection, DeleteSAMLConnection, SAMLConnectionByID and ListSAMLConnections.
Routes
Mounted bya.Mount(r) or a.Handler() under Config.PathPrefix (default /auth). The three SP routes are public:
Connection management is mounted under the organization tree and requires a signed-in user:
Security notes
- Assertions must be signed. An unsigned assertion fails with
ErrSAMLUnsignedAssertion, and other validation failures wrapErrSAMLInvalidAssertion. - SP-initiated AuthnRequest IDs are tracked for
AuthnRequestTTLand consumed on first use, so a replayed response is refused. The SP also accepts unsolicited (IdP-initiated) responses, so restrict who can add a connection. RelayStateis checked against the allow rules above, which prevents open redirects through the login URL.- Keep the SP private key out of source control and rotate it by updating the IdP’s copy of the metadata.
- Pin each connection to the IdP’s real signing certificate in
IdPX509Cert.