如何在Azure AD B2C多流程中持久化AppTenantDomainName查询参数
解决方案:Azure AD B2C 令牌刷新时保留持久化的 AppTenantDomainName 声明
核心问题分析
TokenRefresh流程不会携带初始登录时的查询参数,而当前策略在刷新时仍尝试从查询字符串获取AppTenantDomainName,导致空值覆盖了之前持久化到目录的声明。需要调整策略逻辑,让刷新流程直接读取已存储的声明,而非重新获取。
步骤1:确认声明持久化配置
确保AppTenantDomainName声明已正确定义并配置为持久化到用户目录:
<ClaimsSchema> <ClaimType Id="AppTenantDomainName"> <DisplayName>Application Tenant Domain Name</DisplayName> <DataType>string</DataType> </ClaimType> </ClaimsSchema> <!-- 在登录技术配置文件中添加持久化声明 --> <TechnicalProfile Id="LocalAccountSignIn"> <PersistedClaims> <PersistedClaim ClaimTypeReferenceId="AppTenantDomainName" /> </PersistedClaims> </TechnicalProfile>
步骤2:修改REST API技术配置文件,避免刷新时覆盖
添加预条件,仅当AppTenantDomainName不存在(首次登录场景)时调用REST API,刷新流程直接使用已存储的声明:
<TechnicalProfile Id="REST-EnhanceToken"> <DisplayName>REST API to enhance token</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://your-api-endpoint.com/enhance-token</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="AppTenantDomainName" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="AppTenantDomainName" /> </OutputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> <!-- 仅当声明不存在时调用API,避免刷新时传入空值 --> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>AppTenantDomainName</Value> <Action>SkipThisTechnicalProfile</Action> </Precondition> </Preconditions> </TechnicalProfile>
步骤3:调整TokenRefresh流程的声明读取逻辑
在TokenRefresh用户旅程中,确保从目录读取已持久化的AppTenantDomainName声明:
<UserJourney Id="TokenRefresh"> <OrchestrationSteps> <OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="RefreshTokenSetup" TechnicalProfileReferenceId="TP-RefreshTokenSetup" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney> <!-- 在用户读取技术配置文件中添加输出声明 --> <TechnicalProfile Id="AAD-UserReadUsingObjectId"> <OutputClaims> <OutputClaim ClaimTypeReferenceId="AppTenantDomainName" /> <!-- 其他原有输出声明 --> </OutputClaims> </TechnicalProfile>
步骤4:优化初始登录的参数捕获逻辑
确保仅当查询参数存在时才设置AppTenantDomainName声明,避免空值写入:
<TechnicalProfile Id="LocalAccountSignIn"> <InputClaims> <InputClaim ClaimTypeReferenceId="AppTenantDomainName" DefaultValue="{OAUTH-KV:AppTenantDomainName}" /> </InputClaims> </TechnicalProfile>
验证要点
- 首次登录后,检查Azure AD B2C用户目录中
AppTenantDomainName属性是否已正确存储 - 触发TokenRefresh流程,验证颁发的令牌中
AppTenantDomainName声明与初始值一致 - 测试无查询参数的登录场景,确认不会覆盖已存储的声明
内容的提问来源于stack exchange,提问作者Jaghni Kiran
相关产品推荐
相关产品推荐

