如何将UAE Pass作为身份提供商手动配置到Azure AD B2C?
可以通过Azure AD B2C的**自定义策略(Custom Policy)**手动配置UAE Pass作为身份提供商,无需依赖自动发现的元数据URL。内置的Azure AD B2C用户界面不支持手动输入所有OIDC端点,但自定义策略允许你直接指定所需的各个端点信息。
具体配置步骤:
准备自定义策略基础文件
获取Azure AD B2C官方提供的自定义策略基础模板文件(如TrustFrameworkBase.xml、TrustFrameworkExtensions.xml和SignUpOrSignin.xml),作为配置的基础。编辑TrustFrameworkExtensions.xml添加UAE Pass配置
在文件中添加一个ClaimsProvider节点,包含UAE Pass的所有端点信息、客户端凭证和声明映射:<ClaimsProvider> <Domain>uaepass.ae</Domain> <DisplayName>UAE Pass</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="UAEPass-OIDC"> <DisplayName>UAE Pass</DisplayName> <Protocol Name="OpenIdConnect" /> <Metadata> <Item Key="client_id">你的UAE Pass客户端ID</Item> <Item Key="response_types">code</Item> <Item Key="scope">openid profile</Item> <Item Key="authorization_endpoint">UAE Pass的authorize完整端点URL</Item> <Item Key="token_endpoint">UAE Pass的token完整端点URL</Item> <Item Key="userinfo_endpoint">UAE Pass的userinfo完整端点URL</Item> <Item Key="logout_endpoint">UAE Pass的logout完整端点URL</Item> <Item Key="HttpBinding">POST</Item> <Item Key="UsePolicyInRedirectUri">false</Item> </Metadata> <CryptographicKeys> <Key Id="client_secret" StorageReferenceId="B2C_1A_UAEPassClientSecret" /> </CryptographicKeys> <OutputClaims> <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" /> <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" /> <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="family_name" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" /> <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="uaepass.ae" AlwaysUseDefaultValue="true" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" /> <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" /> <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>存储UAE Pass客户端密钥
在Azure AD B2C租户的「Identity Experience Framework」>「策略密钥」中,创建一个名为B2C_1A_UAEPassClientSecret的密钥,类型选择「字符串」,并填入UAE Pass提供的客户端密钥。更新用户旅程添加UAE Pass选项
在你的登录/注册策略文件(如SignUpOrSignin.xml)中,找到OrchestrationStep类型为CombinedSignInAndSignUp或ClaimsExchange的步骤,添加UAE Pass的身份提供商选择项:<ClaimsProviderSelections> <!-- 保留其他已配置的身份提供商 --> <ClaimsProviderSelection TargetClaimsExchangeId="UAEPassExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <!-- 保留其他已配置的ClaimsExchange --> <ClaimsExchange Id="UAEPassExchange" TechnicalProfileReferenceId="UAEPass-OIDC" /> </ClaimsExchanges>上传并测试自定义策略
将修改后的自定义策略文件上传到Azure AD B2C租户,然后测试登录流程,确认可以通过UAE Pass完成身份验证。
注意事项:
- 确保UAE Pass的端点支持
response_type=code的授权码流程,这是Azure AD B2C要求的OIDC标准流程。 - 根据UAE Pass实际返回的用户声明字段,调整
OutputClaims中的PartnerClaimType映射,保证用户信息能正确同步到Azure AD B2C的用户属性中。
内容的提问来源于stack exchange,提问作者chummy

