IdP attributes identify a principal; local authorization still needs an explicit mapping and tenant rule.
Spring Security SAML attributes: map identity to local authority
Authentication is not permission
A valid assertion may contain department=dispatch. That attribute is input to a local authorization decision, not a command to grant every dispatcher privilege. Spring Security's default authenticated SAML principal can carry attributes with a basic user authority; application roles need an explicit converter or lookup. Method guards should check the resulting local authorities.
Use stable identifiers
A display name and email address can change. Link the assertion's stable subject to a tenant-scoped local account, and decide how deprovisioning reaches active sessions. If two IdPs emit the same subject text, include registration identity in the key. Reject missing or multiply valued required attributes rather than guessing.
Test least privilege
Sign in with no department, an unknown department and a department valid in another tenant. All should have no privileged access. Then sign in with a mapped dispatcher account and assert only the intended shipment command is allowed.
Implementation sketch
record FederatedAccountKey(String registrationId,
String subject, String tenantId) {}
// Resolve this key to a local account before granting command roles.Cost and verification
An account lookup adds I/O at login, not at every request if the result is stored in the session. Revocation needs a session expiry or invalidation contract.
Common Mistakes
- Do not map every authenticated SAML user to an administrator role.
- Do not use email alone as a permanent cross-IdP account key.
- Do not accept a tenant attribute without matching the configured registration and local account.
Read next
Spring Security SAML relying party: align registration, ACS and metadata, Spring method security: authorization advice runs through the bean proxy, Spring JWT tenant claims: reject missing or malformed ownership before conversion.
Related boundary
Spring SAML session revocation: closing the browser is not deprovisioning
