You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure B2C自定义策略中限制OTP重发次数?

限制Azure B2C自定义策略中OTP(邮箱/SMS)的重发次数

要解决邮箱OTP无限重发的问题,你可以通过自定义策略的声明跟踪、声明转换和前置条件验证来实现次数限制,以下是具体步骤:

1. 添加重发次数跟踪声明

在策略的<ClaimsSchema>节点中,新增一个整数类型的声明,用于记录OTP重发次数:

<ClaimsSchema>
  <ClaimType Id="resendCount">
    <DisplayName>OTP重发次数</DisplayName>
    <DataType>int</DataType>
    <DefaultValue>0</DefaultValue>
  </ClaimType>
</ClaimsSchema>

2. 定义次数递增与重置的声明转换

在<ClaimsTransformations>节点中,添加两个转换:一个用于每次重发时递增次数,另一个用于验证成功后重置次数:

<ClaimsTransformations>
  <!-- 递增重发次数 -->
  <ClaimsTransformation Id="IncrementResendCount" TransformationMethod="AddIntegerClaim">
    <InputClaims>
      <InputClaim ClaimTypeReferenceId="resendCount" TransformationClaimType="inputClaim" />
    </InputClaims>
    <InputParameters>
      <InputParameter Id="addAmount" DataType="int" Value="1" />
    </InputParameters>
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="resendCount" TransformationClaimType="outputClaim" />
    </OutputClaims>
  </ClaimsTransformation>

  <!-- 验证成功后重置次数 -->
  <ClaimsTransformation Id="ResetResendCount" TransformationMethod="SetClaimValue">
    <InputParameters>
      <InputParameter Id="claimType" DataType="string" Value="resendCount" />
      <InputParameter Id="value" DataType="int" Value="0" />
    </InputParameters>
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="resendCount" />
    </OutputClaims>
  </ClaimsTransformation>
</ClaimsTransformations>

3. 更新OTP发送技术配置文件

找到处理邮箱OTP发送的技术配置文件(比如示例中的Email-SendOtp),添加以下配置:

  • 在<InputClaimsTransformations>中调用递增次数的转换,每次触发重发时自动计数
  • 添加前置条件,当次数达到阈值(比如3次)时,抛出错误阻止重发
<TechnicalProfile Id="Email-SendOtp">
  <!-- 原有配置保留 -->
  <InputClaimsTransformations>
    <InputClaimsTransformation ReferenceId="IncrementResendCount" />
  </InputClaimsTransformations>
  <Preconditions>
    <Precondition Type="ClaimGreaterThanOrEqual" ExecuteActionsIf="true">
      <Value>resendCount</Value>
      <Value>3</Value> <!-- 这里设置允许的最大重发次数 -->
      <Action>ThrowError</Action>
      <Error>已达到OTP最大重发次数,请稍后重试。</Error>
    </Precondition>
  </Preconditions>
</TechnicalProfile>

4. 验证成功后重置次数

找到验证OTP的技术配置文件(比如Email-VerifyOtp),在<OutputClaimsTransformations>中调用重置次数的转换,确保用户验证成功后,次数计数器归零:

<TechnicalProfile Id="Email-VerifyOtp">
  <!-- 原有配置保留 -->
  <OutputClaimsTransformations>
    <OutputClaimsTransformation ReferenceId="ResetResendCount" />
  </OutputClaimsTransformations>
</TechnicalProfile>

5. 同步限制SMS OTP重发

对于SMS OTP,只需重复步骤3-4,将技术配置文件替换为处理SMS发送的对应ID(比如示例中的Phone-SendOtp)即可实现统一限制。


内容的提问来源于stack exchange,提问作者nullmicgo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 09:18:25