You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C联合登出未完成问题排查:第三方IDP的Identity Token未传递至End Session端点

Azure B2C联合第三方IDP登出时缺少id_token_hint的问题解决

我之前处理过类似的Azure B2C联合登出问题,结合你的描述和配置来看,核心问题大概率是B2C没有正确捕获并存储第三方IDP颁发的id_token,导致触发联合登出时无法将该令牌传递给第三方的End Session端点。以下是具体的排查和解决步骤:

一、问题核心分析

从你的登出流程可以看到,B2C确实发起了到第三方IDP的endsession请求,但缺少id_token_hint参数——这个参数是第三方IDP验证用户身份并完成登出的关键。而B2C之所以无法提供这个参数,是因为登录时没有把第三方的id_token保存到会话中。

二、解决方案步骤

1. 确保捕获并存储第三方IDP的id_token

在你的thirdpartyidp-OAUTH技术配置文件中,需要添加一个OutputClaim来捕获第三方IDP颁发的id_token,并存储到B2C的会话里:

<OutputClaims>
  <!-- 保留你现有的OutputClaims -->
  <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" />
  <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="sub" />
  <OutputClaim ClaimTypeReferenceId="surName" PartnerClaimType="sub" />
  <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="sub" />
  <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication" />
  <OutputClaim ClaimTypeReferenceId="identityProvider" PartnerClaimType="iss" />
  <OutputClaim ClaimTypeReferenceId="identityProviderAccessToken" PartnerClaimType="{oauth2:access_token}" />
  <!-- 添加这一行来捕获id_token -->
  <OutputClaim ClaimTypeReferenceId="idToken" PartnerClaimType="{oauth2:id_token}" />
</OutputClaims>

同时,需要在你的基础策略(比如TrustFrameworkBase.xml)的<ClaimsSchema>中定义idToken这个ClaimType,如果已经存在可以跳过:

<ClaimsSchema>
  <!-- 其他ClaimType定义 -->
  <ClaimType Id="idToken">
    <DisplayName>Third Party ID Token</DisplayName>
    <DataType>string</DataType>
    <AdminHelpText>Stores the ID token issued by the third-party identity provider.</AdminHelpText>
  </ClaimType>
</ClaimsSchema>

2. 检查Session Management技术配置文件

确保你使用的SM-SocialLogin会话管理技术配置文件支持保存和传递第三方令牌。默认的SM-SocialLogin配置通常是这样的,如果你的配置不同,可以调整为:

<TechnicalProfile Id="SM-SocialLogin">
  <DisplayName>Session Management Provider</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.SSO.DefaultSSOSessionProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="IncludeSessionIndex">false</Item>
    <Item Key="RegisterServiceProviders">false</Item>
  </Metadata>
</TechnicalProfile>

这个配置会确保B2C在会话中保存第三方IDP的相关令牌信息,以便登出时使用。

3. 验证第三方IDP的元数据配置

虽然你已经使用了METADATA自动发现,但可以手动指定EndSessionEndpoint来确保B2C正确识别第三方的登出端点(可选,仅当元数据发现异常时使用):

<Metadata>
  <!-- 保留你现有的Metadata条目 -->
  <Item Key="METADATA">https://thirdpartyidp.com/idp/.well-known/openid-configuration</Item>
  <!-- 添加手动指定的EndSessionEndpoint -->
  <Item Key="EndSessionEndpoint">https://thirdpartyidp.com/idp/connect/endsession</Item>
  <Item Key="SingleLogoutEnabled">true</Item>
</Metadata>

三、验证修改效果

完成上述配置修改后,重新上传你的自定义策略,然后执行以下验证步骤:

  • 使用第三方IDP账号登录你的应用
  • 发起登出请求
  • 查看网络请求日志,确认到https://thirdpartyidp.com/idp/connect/endsession的请求中包含id_token_hint参数
  • 验证第三方IDP是否成功完成登出,用户再次访问时需要重新登录

四、关于开箱即用用户流的补充说明

如果你在用户流中也遇到同样问题,需要确保在用户流的第三方IDP配置中启用了单点登出,并且第三方IDP的应用配置中正确设置了登出回调URL(指向B2C的登出端点)。

内容的提问来源于stack exchange,提问作者Kalle M.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 04:07:34