You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在AD B2C自定义策略中使用待颁发令牌调用REST技术配置文件?

在AD B2C自定义策略中使用待颁发JWT调用受保护REST API的方案

可行,你可以在AD B2C令牌生成后、返回给依赖方之前,将该JWT作为Bearer令牌调用REST API。核心思路是在用户旅程的后期步骤中,拦截已生成但未发送的令牌,通过声明转换和REST技术配置文件完成API调用,具体步骤如下:

1. 明确令牌生成时机

AD B2C的ID Token/Access Token是在用户旅程的SendClaims步骤前生成的,我们需要在该步骤之前插入REST API调用,此时令牌已生成但尚未返回给依赖方。

2. 配置REST技术配置文件

创建用于调用API的技术配置文件,指定Bearer认证方式,并将待颁发令牌传入请求头:

<TechnicalProfile Id="CallProtectedApi">
  <DisplayName>调用受保护REST API</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://你的API域名/目标端点</Item>
    <Item Key="AuthenticationType">Bearer</Item>
    <Item Key="SendClaimsIn">Headers</Item>
  </Metadata>
  <InputClaims>
    <!-- 引用待颁发的令牌声明,此处以ID Token为例 -->
    <InputClaim ClaimTypeReferenceId="id_token" PartnerClaimType="Authorization" />
  </InputClaims>
  <InputClaimTransformations>
    <!-- 为令牌添加Bearer前缀,符合HTTP认证格式 -->
    <InputClaimTransformation ReferenceId="AddBearerPrefix" />
  </InputClaims>
</TechnicalProfile>

3. 添加声明转换规则

创建声明转换为令牌拼接Bearer 前缀:

<ClaimTransformation Id="AddBearerPrefix" TransformationMethod="FormatStringClaim">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="id_token" TransformationClaimType="inputClaim" />
  </InputClaims>
  <InputParameters>
    <InputParameter Id="stringFormat" DataType="string" Value="Bearer {0}" />
  </InputParameters>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="id_token" TransformationClaimType="outputClaim" />
  </OutputClaims>
</ClaimTransformation>

4. 修改用户旅程插入API调用

在用户旅程的SendClaims步骤前添加REST调用步骤,确保令牌已生成:

<UserJourney Id="SignUpOrSignIn">
  <OrchestrationSteps>
    <!-- 前置步骤:登录/注册、身份验证等 -->
    <OrchestrationStep Order="5" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="ApiCallExchange" TechnicalProfileReferenceId="CallProtectedApi" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- 最终步骤:向依赖方发送令牌 -->
    <OrchestrationStep Order="6" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
</UserJourney>

5. 暴露待颁发令牌声明

修改JwtIssuer技术配置文件,将待颁发的令牌作为输出声明暴露,确保REST配置可引用:

<TechnicalProfile Id="JwtIssuer">
  <DisplayName>JWT Issuer</DisplayName>
  <Protocol Name="None" />
  <OutputClaims>
    <!-- 保留原有输出声明,新增令牌声明 -->
    <OutputClaim ClaimTypeReferenceId="id_token" />
  </OutputClaims>
  <!-- 其他原有配置 -->
</TechnicalProfile>

关键注意事项

  • 待颁发令牌的受众(aud)是依赖方的客户端ID,需确保你的REST API配置为接受该受众作为有效身份,或在API中添加依赖方客户端ID到允许列表。
  • 若使用Access Token而非ID Token,只需将上述配置中的id_token替换为access_token即可。
  • 需确保API权限配置允许该令牌携带的权限或角色访问目标端点。

内容的提问来源于stack exchange,提问作者gnana sekhar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 12:52:43