Golang Saml Integration

Viewed 218

I tried to implement saml flow in Golang and I used go-saml package. In the go-saml example, they used different Identity Provider. I want to change this Identity Provider with different company IP. Also, I tried to add different metadata xml which designed for my Identity Provider. Here is my code:

package main

import (
    "crypto/rsa"
    "crypto/tls"
    "crypto/x509"
    "fmt"
    "net/http"
    "net/url"
    "os"

    "github.com/crewjam/saml/samlsp"
)

func hello(w http.ResponseWriter, r *http.Request) {
    fmt.Fprintf(w, "Hello, %s!", samlsp.AttributeFromContext(r.Context(), "cn"))
}

func main() {
    keyPair, err := tls.LoadX509KeyPair("myservice.cert", "myservice.key")
    if err != nil {
        panic(err) 
    }
    keyPair.Leaf, err = x509.ParseCertificate(keyPair.Certificate[0])
    if err != nil {
        panic(err) 
    }   
    xmlFile, _ := os.ReadFile("metadata.xml")
    if err != nil {
        fmt.Println(err)
    }
    metadata, err := samlsp.ParseMetadata(xmlFile)
    if err != nil {
        fmt.Println(err)
    }
    rootURL, err := url.Parse("http://localhost:8000")
    if err != nil {
        panic(err) // TODO handle error
    }

    samlSP, _ := samlsp.New(samlsp.Options{
        URL:         *rootURL,
        Key:         keyPair.PrivateKey.(*rsa.PrivateKey),
        Certificate: keyPair.Leaf,
        IDPMetadata: metadata,
    })
    app := http.HandlerFunc(hello)
    http.Handle("/hello", samlSP.RequireAccount(app))
    http.Handle("/saml/", samlSP)
    http.ListenAndServe(":8000", nil)
}

Also, this is content of metadata:

<?xml version="1.0" encoding="utf-8"?>
<md:EntityDescriptor entityID="https://login.test.com.tr" ID="_4a04b975-8da9-4877-8603-935761262d34" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
  <md:IDPSSODescriptor ID="_7c693b4c-76dd-43c8-b5ef-5615d32ef154" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="true">
    <md:KeyDescriptor>
      <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
        <X509Data>
          <X509Certificate>I will add Certificate</X509Certificate>
        </X509Data>
      </KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.test.com.tr/SAML/SService.aspx" />
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.test.com.tr/SAML/SService.aspx" />
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.test.com.tr/SAML/SService.aspx" />
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.test.com.tr/SAML/SService.aspx" />
   
  </md:IDPSSODescriptor>

</md:EntityDescriptor>

The above file was given to me by my customer for test. I just changed link as "test". However when I try to reach "hello" path it routes me the right login page but it gives me an error: "The partner service provider http://localhost:8000/saml/metadata is not configured."

0 Answers
Related