Azure AD B2C:仅邮箱/手机号无密码登录配置问题
自定义策略邮箱OTP登录异常修复方案
问题分析
当前自定义策略支持邮箱/手机号OTP注册登录,手机号登录和注册功能正常,但邮箱登录时仅显示邮箱输入框,无发送验证码按钮及输入框,调整配置后触发内部服务器错误(500)。核心问题是邮箱登录的用户旅程步骤、TechnicalProfile配置未与手机号流程对齐,或存在XML语法/引用错误。
修复步骤
1. 对齐邮箱登录的用户旅程步骤
检查用户旅程中邮箱登录分支的OrchestrationStep,确保包含发送验证码和验证验证码两个关键步骤,与手机号流程结构一致:
<!-- 邮箱登录分支示例 --> <OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="EmailSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-EmailSignin" /> </ClaimsExchanges> </OrchestrationStep> <!-- 添加发送验证码步骤 --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="EmailVerifyCodeExchange" TechnicalProfileReferenceId="Email-SendCode" /> </ClaimsExchanges> </OrchestrationStep> <!-- 添加验证验证码步骤 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="EmailVerifyCodeVerifyExchange" TechnicalProfileReferenceId="Email-VerifyCode" /> </ClaimsExchanges> </OrchestrationStep> <!-- 后续读取用户信息、签发令牌步骤与手机号流程一致 -->
2. 修正邮箱OTP相关TechnicalProfile配置
确保Email-SendCode和Email-VerifyCode的TechnicalProfile与手机号对应配置完全对齐,重点检查以下内容:
- 输入/输出Claim绑定正确(关联
email和verificationCode) - 验证步骤关联正确的OTP发送/验证TechnicalProfile
- 元数据引用正确的UI模板
示例配置:
<TechnicalProfile Id="Email-SendCode"> <DisplayName>Email Send Code</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item> <Item Key="language.button_continue">Send Code</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="email" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="email" /> <OutputClaim ClaimTypeReferenceId="verificationCode" Required="true" /> </OutputClaims> <ValidationTechnicalProfiles> <ValidationTechnicalProfile ReferenceId="AAD-UserReadUsingEmailAddress" /> <ValidationTechnicalProfile ReferenceId="Email-SendOTP" /> </ValidationTechnicalProfiles> </TechnicalProfile> <TechnicalProfile Id="Email-VerifyCode"> <DisplayName>Email Verify Code</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="email" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="verificationCode" Required="true" /> </OutputClaims> <ValidationTechnicalProfiles> <ValidationTechnicalProfile ReferenceId="Email-VerifyOTP" /> <ValidationTechnicalProfile ReferenceId="AAD-UserReadUsingEmailAddress" /> </ValidationTechnicalProfiles> </TechnicalProfile>
3. 验证ClaimType定义
确保email ClaimType正确配置为用户可输入类型:
<ClaimType Id="email"> <DisplayName>Email Address</DisplayName> <DataType>string</DataType> <UserInputType>TextBox</UserInputType> <Restriction> <Pattern RegularExpression="^[a-zA-Z0-9.!#$%&'^_`{}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*$" HelpText="Please enter a valid email address." /> </Restriction> </ClaimType>
4. 排查内部服务器错误(500)
- 开启策略调试模式,查看Azure AD B2C的详细错误日志,定位具体错误原因(如XML标签未闭合、引用不存在的TechnicalProfile/ClaimType)
- 检查所有自定义策略文件的XML语法,确保无拼写错误或格式问题
验证修复
完成配置调整后,测试邮箱登录流程:
- 进入邮箱登录页面,输入邮箱地址
- 确认页面显示发送验证码按钮
- 点击按钮后接收验证码,页面显示验证码输入框
- 输入验证码后完成登录,流程与手机号登录完全一致
内容的提问来源于stack exchange,提问作者MavWolverine
相关产品推荐
相关产品推荐

