You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C配置带只读Email字段的自定义重置密码策略

重置密码流程中Email字段改为只读预填充的实现方案

问题背景

需要将重置密码时的常规Email验证字段,改为可通过id_token_hint和login_hint预填充的只读字段。当前配置自定义重置密码策略后,页面出现两个Email字段(一个只读、一个可输入);若移除trustframeworkbase策略中LocalAccountReadPasswordUsingObjectId的email声明,重复字段消失但密码重置无法完成(推测该字段为必填项)。


实现步骤

1. 定义只读Email声明

在自定义策略的<ClaimsSchema>中添加readonlyEmail声明,指定为只读输入类型:

<ClaimType Id="readonlyEmail">
  <DisplayName>Email Address</DisplayName>
  <DataType>string</DataType>
  <UserInputType>Readonly</UserInputType>
</ClaimType>

2. 配置声明转换,提取预填充邮箱值

添加声明转换规则,将传入的login_hint或id_token_hint中的邮箱值映射到readonlyEmail:

  • 从login_hint提取:
<ClaimsTransformation Id="ExtractEmailFromLoginHint" TransformationMethod="FormatStringClaim">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="login_hint" TransformationClaimType="inputClaim" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="readonlyEmail" TransformationClaimType="outputClaim" />
  </OutputClaims>
</ClaimsTransformation>
  • 从id_token_hint提取:需添加JWT解析的声明转换,将令牌中的邮箱声明赋值给readonlyEmail。

3. 修改技术配置文件,替换显示字段

在LocalAccountReadPasswordUsingObjectId等重置密码相关技术配置文件中:

  • 保留email声明的读取逻辑(后端流程需要该字段定位用户);
  • 在<InputClaims>中替换显示字段为readonlyEmail,并设置默认值为读取到的email:
<InputClaim ClaimTypeReferenceId="readonlyEmail" DefaultValue="{Claim:email}" />
  • 移除原email的输入声明,避免页面渲染可输入字段。

4. 同步只读字段到必填声明

添加声明转换,将readonlyEmail的值同步到email字段,满足后端必填校验:

<ClaimsTransformation Id="CopyReadonlyEmailToEmail" TransformationMethod="CopyClaim">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="readonlyEmail" TransformationClaimType="inputClaim" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="email" TransformationClaimType="outputClaim" />
  </OutputClaims>
</ClaimsTransformation>

在技术配置文件的<ClaimsTransformations>节点中引入该转换,确保email声明始终有值。

5. 调整用户旅程与页面布局

  • 在重置密码的用户旅程步骤中,确保readonlyEmail被正确传递并作为页面显示字段;
  • 自定义页面布局时,确认仅渲染readonlyEmail字段,不加载原email字段。

关键注意点

  • 不可直接删除LocalAccountReadPasswordUsingObjectId中的email声明,后端重置流程依赖该字段定位用户;
  • 通过声明转换同步字段值,既实现页面只读显示,又满足后端必填校验;
  • 确保id_token_hint和login_hint在策略入口处被正确解析,顺利赋值给readonlyEmail。

内容的提问来源于stack exchange,提问作者Nathan Ohere

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 09:16:18