如何在Azure AD B2C自定义策略中传递用户输入值至其他技术配置文件
Azure AD B2C自定义策略:传递用户输入到REST API技术配置文件
问题场景
开发Azure AD B2C自定义策略时,需要将用户在自断言技术配置文件SelfAsserted-LocalAccountSignin-Email中输入的邮箱(signInName)和密码(password)传递到REST API技术配置文件REST-API-SignUp,用于向自定义数据库验证用户身份。尝试使用ClaimsTransformations未成功,寻求正确实现方法及配置规则。
现有代码
REST API技术配置文件
<TechnicalProfile Id="REST-API-SignUp"> <DisplayName>Validate user's input data and return loyaltyNumber claim</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://146a-112-134-225-150.ngrok-free.app/api/auth/login</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> </Metadata> </TechnicalProfile>
自断言登录技术配置文件
<!-- This technical profile uses a validation technical profile to authenticate the user. --> <TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email"> <DisplayName>Local Account Signin</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="SignUpTarget">SignUpWithLogonEmailExchange</Item> <Item Key="setting.operatingMode">Email</Item> <Item Key="ContentDefinitionReferenceId">api.localaccountsignin</Item> <Item Key="IncludeClaimResolvingInClaimsHandling">true</Item> </Metadata> <IncludeInSso>false</IncludeInSso> <InputClaims> <InputClaim ClaimTypeReferenceId="signInName" /> <InputClaim ClaimTypeReferenceId="password" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="signInName" Required="true" /> <OutputClaim ClaimTypeReferenceId="password" Required="true" /> <OutputClaim ClaimTypeReferenceId="objectId" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" /> </OutputClaims> <ValidationTechnicalProfiles> <ValidationTechnicalProfile ReferenceId="login-NonInteractive" /> </ValidationTechnicalProfiles> <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" /> </TechnicalProfile>
编排步骤
<OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin"> <ClaimsProviderSelections> <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="2" Type="ClaimsExchange" ContentDefinitionReferenceId="api.localaccountpasswordreset"> <ClaimsProviderSelections> <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="RestApiSignUp" TechnicalProfileReferenceId="REST-API-SignUp" /> </ClaimsExchanges> </OrchestrationStep>
正确实现方法及配置规则
1. 确保声明类型(ClaimType)已定义
首先确认signInName和password已在策略的<ClaimsSchema>节点中定义,示例如下:
<ClaimsSchema> <ClaimType Id="signInName"> <DisplayName>Email Address</DisplayName> <DataType>string</DataType> <UserHelpText>Enter your email address</UserHelpText> <UserInputType>TextBox</UserInputType> </ClaimType> <ClaimType Id="password"> <DisplayName>Password</DisplayName> <DataType>string</DataType> <UserHelpText>Enter your password</UserHelpText> <UserInputType>Password</UserInputType> </ClaimType> </ClaimsSchema>
2. 配置REST API技术配置文件接收声明
在REST-API-SignUp中添加<InputClaims>节点,明确指定要接收的signInName和password声明。由于SendClaimsIn设置为Body,这些声明会自动以JSON键值对的形式放入请求体中:
<TechnicalProfile Id="REST-API-SignUp"> <DisplayName>Validate user's input data and return loyaltyNumber claim</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://146a-112-134-225-150.ngrok-free.app/api/auth/login</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> </Metadata> <!-- 添加InputClaims接收声明 --> <InputClaims> <InputClaim ClaimTypeReferenceId="signInName" /> <InputClaim ClaimTypeReferenceId="password" /> </InputClaims> </TechnicalProfile>
3. 调整编排步骤
第二个编排步骤类型为ClaimsExchange,无需ClaimsProviderSelections节点(该节点用于身份提供商选择),修改后如下:
<OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="RestApiSignUp" TechnicalProfileReferenceId="REST-API-SignUp" /> </ClaimsExchanges> </OrchestrationStep>
4. 可选:移除默认AAD验证(若仅使用自定义数据库验证)
原自断言技术配置文件中的<ValidationTechnicalProfiles>会调用login-NonInteractive验证Azure AD中的用户。如果仅需通过自定义REST API验证用户身份,需移除该节点,避免双重验证:
<TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email"> <!-- 其他配置保持不变 --> <!-- 移除以下节点 --> <!-- <ValidationTechnicalProfiles> <ValidationTechnicalProfile ReferenceId="login-NonInteractive" /> </ValidationTechnicalProfiles> --> </TechnicalProfile>
核心配置规则
- 声明一致性:前后技术配置引用的
ClaimTypeReferenceId必须完全一致,确保声明能在步骤间传递。 - 输出声明暴露:自断言技术配置文件需在
<OutputClaims>中包含要传递的声明,确保这些声明被加入到用户的声明包中。 - 输入声明接收:REST技术配置文件需通过
<InputClaims>声明要接收的声明,B2C会自动从声明包中提取值并传递。 - 步骤顺序:编排步骤必须按逻辑顺序执行,先获取用户输入的步骤,再执行REST调用步骤。
- 请求格式:
SendClaimsIn设置为Body时,InputClaims中的声明会自动序列化为JSON请求体;若设置为QueryString,则会作为URL参数传递。
内容的提问来源于stack exchange,提问作者Shehan V
相关产品推荐
相关产品推荐

