mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-05 00:29:48 +03:00
SAML SingleLogoutService Issues with ADFS #1563
Closed
opened 2026-02-05 01:16:12 +03:00 by OVERLORD
·
6 comments
No Branch/Tag Specified
development
l10n_development
further_theme_development
release
llm_only
vectors
v25-11
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#1563
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @SoarinFerret on GitHub (Mar 1, 2020).
Describe the bug
I believe I have uncovered two issues when setting up SAML with ADFS, not sure if I need to supply multiple bug reports or not.
app/config/saml2.phpand providing the certificate as an environment variable.urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress. However, Bookstack is sending backurn:oasis:names:tc:SAML:2.0:nameid-format:entity. In addition, the NameID should be my UPN / E-Mail address, but instead it appears to be sending an ADFS URL.Here is the sample response:
Here is the error generated on ADFS after receiving that:
Steps To Reproduce
Steps to reproduce the behavior:
Expected behavior
I believe I should be expecting 2 things:
Your Configuration (please complete the following information):
Additional context
Add any other context about the problem here.
Here is my
.envrelevant SAML config:And here are my ADFS claims rules:
@SoarinFerret commented on GitHub (Feb 15, 2021):
I was recently reached out to for help with this, I figured I would update this issue. I actually have gotten this configuration working without using SLS. More details can be found here: https://blog.kanto.cloud/bookstack-adfs-setup/
The gist of of it is choosing to manually define your parameters for ADFS instead of using the autoload from the federation metadata. This prevents Bookstack from automatically trying to use SLS. Here is the relevant
.envfor my ADFS SAML config:I still have intentions of one day finishing my other patch, because SLS is cool, but it is not a necessity for me at the moment.
@dani commented on GitHub (Mar 17, 2021):
I do have a similar issue with Lemonldap::NG as SAML IDP. SLO can't work because the the NameID isn't correct. Lemonldap::NG can't make sense of the request so respond with a code 400
@coudot commented on GitHub (Mar 17, 2021):
The issue is in this part of the code:
65ddd16532/app/Auth/Access/Saml2Service.php (L60)The logout method should be called with correct arguments, see https://github.com/onelogin/php-saml#initiate-slo
At least the correct NameID and SessionIndex that should be registered in user session when he authenticates.
@theodor-franke commented on GitHub (Aug 30, 2021):
Is there a solution?
@theodor-franke commented on GitHub (Aug 30, 2021):
#2902 I created a PR that should resolve this Issue
@ssddanbrown commented on GitHub (Oct 25, 2021):
As per #2902 a range of changes have now been made for BookStack v21.10.
The new
SAML2_SP_x509andSAML2_SP_x509_KEYoptions, which enable SP SLS signing, can be seen in the updated documentation:https://www.bookstackapp.com/docs/admin/saml2-auth/
Will therefore close this off but please open a new issue if there are problems with the updated implementation.