You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure AD B2C多流程中持久化AppTenantDomainName查询参数

解决方案:Azure AD B2C 令牌刷新时保留持久化的 AppTenantDomainName 声明

核心问题分析

TokenRefresh流程不会携带初始登录时的查询参数,而当前策略在刷新时仍尝试从查询字符串获取AppTenantDomainName,导致空值覆盖了之前持久化到目录的声明。需要调整策略逻辑,让刷新流程直接读取已存储的声明,而非重新获取。

步骤1:确认声明持久化配置

确保AppTenantDomainName声明已正确定义并配置为持久化到用户目录:

<ClaimsSchema>
  <ClaimType Id="AppTenantDomainName">
    <DisplayName>Application Tenant Domain Name</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
</ClaimsSchema>

<!-- 在登录技术配置文件中添加持久化声明 -->
<TechnicalProfile Id="LocalAccountSignIn">
  <PersistedClaims>
    <PersistedClaim ClaimTypeReferenceId="AppTenantDomainName" />
  </PersistedClaims>
</TechnicalProfile>

步骤2:修改REST API技术配置文件,避免刷新时覆盖

添加预条件,仅当AppTenantDomainName不存在(首次登录场景)时调用REST API,刷新流程直接使用已存储的声明:

<TechnicalProfile Id="REST-EnhanceToken">
  <DisplayName>REST API to enhance token</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://your-api-endpoint.com/enhance-token</Item>
    <Item Key="AuthenticationType">None</Item>
    <Item Key="SendClaimsIn">Body</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="AppTenantDomainName" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="AppTenantDomainName" />
  </OutputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
  <!-- 仅当声明不存在时调用API,避免刷新时传入空值 -->
  <Preconditions>
    <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
      <Value>AppTenantDomainName</Value>
      <Action>SkipThisTechnicalProfile</Action>
    </Precondition>
  </Preconditions>
</TechnicalProfile>

步骤3:调整TokenRefresh流程的声明读取逻辑

在TokenRefresh用户旅程中,确保从目录读取已持久化的AppTenantDomainName声明:

<UserJourney Id="TokenRefresh">
  <OrchestrationSteps>
    <OrchestrationStep Order="1" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="RefreshTokenSetup" TechnicalProfileReferenceId="TP-RefreshTokenSetup" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="2" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
  <ClientDefinition ReferenceId="DefaultWeb" />
</UserJourney>

<!-- 在用户读取技术配置文件中添加输出声明 -->
<TechnicalProfile Id="AAD-UserReadUsingObjectId">
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="AppTenantDomainName" />
    <!-- 其他原有输出声明 -->
  </OutputClaims>
</TechnicalProfile>

步骤4:优化初始登录的参数捕获逻辑

确保仅当查询参数存在时才设置AppTenantDomainName声明,避免空值写入:

<TechnicalProfile Id="LocalAccountSignIn">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="AppTenantDomainName" DefaultValue="{OAUTH-KV:AppTenantDomainName}" />
  </InputClaims>
</TechnicalProfile>

验证要点

  1. 首次登录后,检查Azure AD B2C用户目录中AppTenantDomainName属性是否已正确存储
  2. 触发TokenRefresh流程,验证颁发的令牌中AppTenantDomainName声明与初始值一致
  3. 测试无查询参数的登录场景,确认不会覆盖已存储的声明

内容的提问来源于stack exchange,提问作者Jaghni Kiran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 00:47:37