You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure AD B2C令牌中返回GUID?自定义策略配置疑问

Azure AD B2C自定义策略生成并返回GUID的实现步骤

核心结论

可以将GUID生成操作添加到OrchestrationStep中,具体需完成以下几个关键配置环节:

1. 定义GUID声明类型

在自定义策略的<ClaimsSchema>节点下添加用于存储GUID的声明类型:

<ClaimsSchema>
  <ClaimType Id="generatedGuid">
    <DisplayName>Generated GUID</DisplayName>
    <DataType>string</DataType>
    <UserHelpText>每次登录/注册生成的唯一GUID</UserHelpText>
  </ClaimType>
</ClaimsSchema>

2. 配置GUID生成的ClaimTransformer

在<ClaimsTransformations>节点下添加生成GUID的转换器,使用CreateRandomString方法生成标准格式GUID:

<ClaimsTransformations>
  <ClaimsTransformation Id="GenerateGuid" TransformationMethod="CreateRandomString">
    <InputParameters>
      <InputParameter Id="randomGeneratorType" DataType="string" Value="GUID" />
    </InputParameters>
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="generatedGuid" TransformationClaimType="outputClaim" />
    </OutputClaims>
  </ClaimsTransformation>
</ClaimsTransformations>

3. 将生成操作添加到OrchestrationStep

在用户旅程的<OrchestrationSteps>中,选择合适位置(建议在用户身份验证完成后、返回声明前)新增步骤,调用上述转换器:

<OrchestrationSteps>
  <!-- 保留已有步骤 -->
  <OrchestrationStep Order="X" Type="ClaimsExchange">
    <ClaimsExchanges>
      <ClaimsExchange Id="GenerateGuidExchange" TechnicalProfileReferenceId="GenerateGuidTechProfile" />
    </ClaimsExchanges>
  </OrchestrationStep>
  <!-- 后续返回声明的步骤 -->
</OrchestrationSteps>

4. 创建对应的TechnicalProfile

在<TechnicalProfiles>节点下定义调用转换器的技术配置文件:

<TechnicalProfiles>
  <TechnicalProfile Id="GenerateGuidTechProfile">
    <DisplayName>生成GUID</DisplayName>
    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="generatedGuid" />
    </OutputClaims>
    <OutputClaimsTransformations>
      <OutputClaimsTransformation ReferenceId="GenerateGuid" />
    </OutputClaimsTransformations>
    <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
  </TechnicalProfile>
</TechnicalProfiles>

5. 确保GUID声明被返回给应用

在返回应用的技术配置文件(如JwtIssuer)中,将generatedGuid添加到<OutputClaims>,使令牌包含该GUID:

<TechnicalProfile Id="JwtIssuer">
  <!-- 保留已有配置 -->
  <OutputClaims>
    <!-- 保留已有声明 -->
    <OutputClaim ClaimTypeReferenceId="generatedGuid" />
  </OutputClaims>
  <!-- 保留已有配置 -->
</TechnicalProfile>

注意事项

  • 步骤顺序需合理:GUID生成要在用户身份验证完成后执行,避免未验证用户就生成GUID。
  • 若无需持久化,不用将该GUID存储到用户目录,每次登录/注册都会生成新值。
  • 新手建议先在测试环境修改验证,确认生效后再部署到生产环境。

内容的提问来源于stack exchange,提问作者Jemshith T K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 19:15:19