Azure AD B2C自定义策略能否基于来源URL动态选择外部IdP?
基于来源URL动态选择外部IdP实现静默SSO的方案
可以通过Azure AD B2C自定义策略实现你的需求,具体实现步骤如下:
1. 捕获来源上下文信息
首先需要在自定义策略中捕获用户的来源URL(或自定义来源参数)。考虑到浏览器对referrer的限制(比如跨域场景下可能无法获取),建议前端传递自定义参数(如source),如果依赖referrer也可以直接捕获:
先在
<ClaimsSchema>中定义存储来源信息的声明:<ClaimType Id="sourceContext"> <DisplayName>Source Context</DisplayName> <DataType>string</DataType> </ClaimType>创建技术配置文件来获取请求中的来源参数:
<TechnicalProfile Id="RetrieveSourceContext"> <DisplayName>Get Source Context from Request</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <InputClaims> <!-- 这里可以用referrer或者自定义的source参数 --> <InputClaim ClaimTypeReferenceId="sourceContext" PartnerClaimType="referrer" DefaultValue="" /> <!-- 如果用自定义参数,替换为:<InputClaim ClaimTypeReferenceId="sourceContext" PartnerClaimType="source" DefaultValue="" /> --> </InputClaims> </TechnicalProfile>将这个技术配置文件添加到用户旅程的起始步骤,确保在选择IdP前完成信息捕获。
2. 根据来源动态跳转至对应外部IdP
通过编排步骤的Precondition条件判断,自动跳过IdP选择界面,直接跳转到匹配的外部IdP授权端点:
<!-- 步骤1:默认IdP选择界面(仅当无匹配来源时显示) --> <OrchestrationStep Order="1" Type="ClaimsProviderSelection" ContentDefinitionReferenceId="api.idpselections"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>sourceContext</Value> <Value>https://referrer-a.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>sourceContext</Value> <Value>https://referrer-b.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>sourceContext</Value> <Value>https://referrer-c.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsProviderSelections> <ClaimsProviderSelection TargetClaimsExchangeId="IdP-A" /> <ClaimsProviderSelection TargetClaimsExchangeId="IdP-B" /> <ClaimsProviderSelection TargetClaimsExchangeId="IdP-C" /> </ClaimsProviderSelections> </OrchestrationStep> <!-- 步骤2:来源A自动跳转至IdP-A --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>sourceContext</Value> <Value>https://referrer-a.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="IdP-A" TechnicalProfileReferenceId="IdP-A-OAuth2" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤3:来源B自动跳转至IdP-B --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>sourceContext</Value> <Value>https://referrer-b.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="IdP-B" TechnicalProfileReferenceId="IdP-B-OAuth2" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤4:来源C自动跳转至IdP-C --> <OrchestrationStep Order="4" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>sourceContext</Value> <Value>https://referrer-c.com</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="IdP-C" TechnicalProfileReferenceId="IdP-C-OAuth2" /> </ClaimsExchanges> </OrchestrationStep>
3. 配置静默SSO模式
在每个外部IdP的技术配置文件中,添加静默授权相关的元数据,确保使用授权码流且无交互:
<TechnicalProfile Id="IdP-A-OAuth2"> <DisplayName>IdP A</DisplayName> <Protocol Name="OAuth2" /> <Metadata> <Item Key="AuthorizationEndpoint">https://idp-a.com/authorize</Item> <Item Key="TokenEndpoint">https://idp-a.com/token</Item> <Item Key="response_types">code</Item> <Item Key="scope">openid profile</Item> <Item Key="prompt">none</Item> <!-- 启用静默模式,无用户交互 --> <Item Key="HttpBinding">POST</Item> <!-- 其他必要配置:ClientId、ClientSecret等 --> </Metadata> <!-- 输入输出声明配置 --> </TechnicalProfile>
关键注意事项
- 来源参数可靠性:依赖
referrer可能存在跨域限制或被篡改的风险,优先使用前端传递的自定义source参数。 - 会话有效性:静默SSO依赖用户在对应外部IdP的有效会话,若会话已过期,IdP会返回错误,需在策略中添加 fallback 逻辑(比如跳转到IdP登录界面)。
- 信任关系配置:确保Azure AD B2C与所有外部IdP的信任关系已正确配置,包括回调URL、客户端凭证等。
内容的提问来源于stack exchange,提问作者Andrew Tyson
相关产品推荐
相关产品推荐

