You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C ROPC自定义策略:如何在验证密码前读取用户名?

Azure AD B2C ROPC流程用户迁移前置检查解决方案

错误原因说明

ROPC OAuth流的协议参数解析(提取请求中的username和password)是由ResourceOwnerPasswordCredentials-OAUTH2这个专属技术配置实现的,自定义声明转换或其他非ROPC技术配置无法处理ROPC请求的参数格式,因此首步必须指定该技术配置,否则B2C会因无法识别请求类型抛出The method or operation is not implemented.错误。

可行策略调整方案

无需修改首步的ROPC技术配置,而是将前置检查逻辑插入到ROPC参数提取之后的编排步骤中,具体流程如下:

  1. 首步保留ResourceOwnerPasswordCredentials-OAUTH2,获取用户提交的用户名和密码声明
  2. 执行用户名提取/格式转换(如果需要)
  3. 检查用户是否需要迁移
  4. 根据迁移状态分支处理:
    • 无需迁移:直接验证本地B2C密码
    • 需要迁移:先验证远程B2C用户密码,同步密码到本地并标记迁移状态,再完成本地验证
  5. 生成并返回令牌

关键策略代码示例

用户旅程编排步骤

<UserJourney Id="SignIn_ROPC_UserMigration">
  <OrchestrationSteps>
    <!-- 步骤1:必须优先提取ROPC请求的用户名密码 -->
    <OrchestrationStep Order="1" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="ROPC_Credentials_Exchange" TechnicalProfileReferenceId="ResourceOwnerPasswordCredentials-OAUTH2" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤2:提取/格式化用户名(若无需处理可跳过,直接使用signInName声明) -->
    <OrchestrationStep Order="2" Type="ClaimsTransformation">
      <ClaimsTransformations>
        <ClaimsTransformationReferenceId="ClaimTransformation-ExtractUsername" />
      </ClaimsTransformations>
    </OrchestrationStep>

    <!-- 步骤3:调用自定义检查逻辑,判断用户是否需要迁移 -->
    <OrchestrationStep Order="3" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="Check_Migration_Status" TechnicalProfileReferenceId="REST-CheckMigrationStatus" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤4:处理用户迁移逻辑(仅当需要迁移时执行) -->
    <OrchestrationStep Order="4" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>needsMigration</Value>
          <Value>false</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <!-- 验证远程B2C用户密码 -->
        <ClaimsExchange Id="Remote_B2C_ROPC_Validation" TechnicalProfileReferenceId="RemoteB2C-ROPC-Auth" />
        <!-- 同步密码到本地并标记已迁移 -->
        <ClaimsExchange Id="Sync_Password_Mark_Migrated" TechnicalProfileReferenceId="REST-SyncPasswordAndMarkMigrated" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤5:验证本地B2C用户密码 -->
    <OrchestrationStep Order="5" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="Local_Account_SignIn" TechnicalProfileReferenceId="LocalAccountSigninEmailPassword" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤6:生成并返回令牌 -->
    <OrchestrationStep Order="6" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
  <ClientDefinition ReferenceId="DefaultWeb" />
</UserJourney>

核心技术配置说明

  • ResourceOwnerPasswordCredentials-OAUTH2:保留默认ROPC配置,确保正确提取signInName和password声明
  • REST-CheckMigrationStatus:自定义REST API技术配置,接收signInName并返回needsMigration布尔值声明
  • RemoteB2C-ROPC-Auth:配置为远程B2C的ROPC验证技术,验证用户密码有效性
  • REST-SyncPasswordAndMarkMigrated:调用REST API将远程用户密码同步到本地B2C,并更新用户属性标记迁移完成

内容的提问来源于stack exchange,提问作者Daniele Francioni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 05:23:33