You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C自定义策略:定制登录输入与联合注册验证需求咨询

Azure B2C自定义策略:联合唯一标识注册与双模式登录实现方案

注册环节:部门+用户ID联合唯一性验证

  1. 添加自定义声明
    在策略的<ClaimsSchema>节点中定义部门和用户ID的声明:
<ClaimsSchema>
  <ClaimType Id="departmentName">
    <DisplayName>部门名称</DisplayName>
    <DataType>string</DataType>
    <UserInputType>TextBox</UserInputType>
    <UserHelpText>请输入您所在的部门名称</UserHelpText>
  </ClaimType>
  <ClaimType Id="userId">
    <DisplayName>用户ID</DisplayName>
    <DataType>string</DataType>
    <UserInputType>TextBox</UserInputType>
    <UserHelpText>请输入您的专属用户ID</UserHelpText>
  </ClaimType>
</ClaimsSchema>
  1. 实现联合唯一性校验
    Azure B2C默认不支持多字段联合唯一,需通过REST API自定义验证:
  • 搭建一个REST服务,接收departmentName和userId参数,查询Azure AD B2C用户存储(可通过Microsoft Graph API)判断组合是否已存在。
  • 在注册用户旅程中添加验证步骤,调用该REST技术配置文件:
<OrchestrationStep Order="3" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="CheckUniqueDepartmentUserId" TechnicalProfileReferenceId="REST-CheckUniqueDepartmentUserId" />
  </ClaimsExchanges>
</OrchestrationStep>
  • 配置REST技术配置文件,指定请求参数和验证逻辑:
<TechnicalProfile Id="REST-CheckUniqueDepartmentUserId">
  <DisplayName>Check Department + UserId Uniqueness</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://your-rest-service-url.com/check-unique</Item>
    <Item Key="SendClaimsIn">Body</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="departmentName" />
    <InputClaim ClaimTypeReferenceId="userId" />
  </InputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>
  1. 持久化自定义属性
    在注册技术配置文件的<PersistedClaims>中添加两个字段,确保用户数据被存储:
<PersistedClaims>
  <PersistedClaim ClaimTypeReferenceId="departmentName" />
  <PersistedClaim ClaimTypeReferenceId="userId" />
  <PersistedClaim ClaimTypeReferenceId="password" />
  <!-- 其他默认字段如email、displayName等 -->
</PersistedClaims>

登录环节:双模式登录实现

模式1:组合用户名(departmentName_userId)+密码登录

  1. 拆分组合用户名
    添加声明转换实现字符串拆分:
<ClaimsTransformations>
  <ClaimsTransformation Id="SplitCombinedUsername" TransformationMethod="SplitString">
    <InputClaims>
      <InputClaim ClaimTypeReferenceId="signInName" TransformationClaimType="inputClaim" />
    </InputClaims>
    <InputParameters>
      <InputParameter Id="delimiter" DataType="string" Value="_" />
    </InputParameters>
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="departmentName" TransformationClaimType="outputClaim1" />
      <OutputClaim ClaimTypeReferenceId="userId" TransformationClaimType="outputClaim2" />
    </OutputClaims>
  </ClaimsTransformation>
</ClaimsTransformations>
  1. 修改登录技术配置
    在登录技术配置文件中添加该转换,再调用REST验证组合是否匹配:
<TechnicalProfile Id="LocalAccountSignInWithCombinedUsername">
  <DisplayName>Combined Username Sign In</DisplayName>
  <Protocol Name="OpenIdConnect" />
  <InputClaimsTransformations>
    <InputClaimsTransformation ReferenceId="SplitCombinedUsername" />
  </InputClaimsTransformations>
  <ClaimsExchanges>
    <ClaimsExchange Id="REST-ValidateCombinedLogin" TechnicalProfileReferenceId="REST-ValidateCombinedLogin" />
  </ClaimsExchanges>
  <!-- 其他配置如输入声明、会话管理等 -->
</TechnicalProfile>

REST验证服务需根据拆分后的departmentName和userId找到用户,再校验密码正确性。

模式2:三输入框(部门+用户ID+密码)登录

  1. 自定义登录页面UI
    在<ContentDefinition>中修改登录页面的HTML模板,添加部门和用户ID的输入框:
<div class="form-group">
  <label for="departmentName">部门名称</label>
  <input type="text" id="departmentName" name="departmentName" class="form-control" required />
</div>
<div class="form-group">
  <label for="userId">用户ID</label>
  <input type="text" id="userId" name="userId" class="form-control" required />
</div>
<div class="form-group">
  <label for="password">密码</label>
  <input type="password" id="password" name="password" class="form-control" required />
</div>
  1. 配置登录技术配置文件
    创建专门的技术配置文件接收三个输入声明,调用REST服务验证:
<TechnicalProfile Id="LocalAccountSignInWithThreeFields">
  <DisplayName>Three-Field Sign In</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.signin</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="departmentName" />
    <InputClaim ClaimTypeReferenceId="userId" />
    <InputClaim ClaimTypeReferenceId="password" />
  </InputClaims>
  <ClaimsExchanges>
    <ClaimsExchange Id="REST-ValidateThreeFieldLogin" TechnicalProfileReferenceId="REST-ValidateThreeFieldLogin" />
  </ClaimsExchanges>
</TechnicalProfile>
  1. 用户旅程中支持两种登录方式
    在用户旅程中添加选择步骤,让用户切换登录模式,或者同时提供两种入口:
<OrchestrationStep Order="1" Type="CombinedSignInAndSignUp">
  <ClaimsProviderSelections>
    <ClaimsProviderSelection TargetClaimsExchangeId="CombinedUsernameExchange" />
    <ClaimsProviderSelection TargetClaimsExchangeId="ThreeFieldExchange" />
  </ClaimsProviderSelections>
  <!-- 其他配置 -->
</OrchestrationStep>

核心参考要点

  • 声明转换(ClaimsTransformation):处理字符串拆分/组合,是实现用户名格式转换的基础。
  • REST技术配置文件:所有自定义验证逻辑(联合唯一、登录校验)的核心载体,需自行实现后端服务。
  • 用户旅程(UserJourney):控制注册/登录流程的步骤顺序,实现多模式登录的切换。
  • 内容定义(ContentDefinition):自定义UI元素,适配多输入框的登录页面需求。

内容的提问来源于stack exchange,提问作者Dyy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 10:29:57