AAD B2C自定义策略REST API调用:如何同时在URL和Body传声明
在AAD B2C自定义策略中实现部分声明放URL、部分放请求体的REST调用
你遇到的问题可以通过AAD B2C的**声明解析器(Claim Resolver)**特性解决,不需要修改SendClaimsIn的全局设置,具体调整如下:
关键配置说明
- URL占位符自动替换:你已设置
<Item Key="ClaimResolverUrlFormatting">true</Item>,这个配置会自动识别URL中的{groupId}占位符,并使用同名输入声明的值进行替换,该逻辑独立于SendClaimsIn的设置。 - 请求体单独配置:保持
SendClaimsIn为Body,同时通过ClaimUsedForRequestPayload指定放入请求体的声明graphUserUri,需确保该声明内容符合目标API要求的格式(比如Graph API添加组成员需要的{"@odata.id": "user-uri"}结构)。
修改后的完整技术配置文件
<TechnicalProfile Id="REST-AddUserToGroup"> <DisplayName>Add user to group using Graph API</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://bfc8-77-252-160-45.ngrok-free.app/v1.0/groups/{groupId}/members/$ref</Item> <Item Key="SendClaimsIn">Body</Item> <Item Key="ClaimUsedForRequestPayload">graphUserUri</Item> <Item Key="AuthenticationType">Bearer</Item> <Item Key="UseClaimAsBearerToken">bearerToken</Item> <Item Key="ClaimResolverUrlFormatting">true</Item> <Item Key="DebugMode">true</Item> </Metadata> <InputClaimsTransformations> <InputClaimsTransformation ReferenceId="REST-AddUserToGroup-UserUri"/> </InputClaimsTransformations> <InputClaims> <InputClaim ClaimTypeReferenceId="groupId" /> <InputClaim ClaimTypeReferenceId="graphUserUri" /> <InputClaim ClaimTypeReferenceId="bearerToken" /> </InputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile>
额外注意事项
- 确认
groupId声明在调用该技术配置文件前已被正确赋值(比如从前置流程获取或转换得到)。 - 检查
graphUserUri声明的内容格式是否匹配目标API要求,例如针对Graph API添加组成员,该声明值应为类似{"@odata.id": "https://graph.microsoft.com/v1.0/users/{objectId}"}的JSON字符串,可通过声明转换构造该格式。
内容的提问来源于stack exchange,提问作者Abdul Qadir Memon
相关产品推荐
相关产品推荐

