You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义策略中解码id_token_hint声明时出现Base64异常

Azure AD B2C ID Token Hint 处理异常问题

我基于B2C Samples的邮件邀请示例进行适配,仅添加了令牌受众验证参数,未对策略本身做实质性修改,但已将令牌颁发者调整为从Azure Key Vault获取证书。

生成的令牌签名可通过令牌颁发者发布的元数据在jwt.io上验证通过(包含示例令牌验证),因此我确信签名令牌是有效的。但在处理id_token_hint的GetClaims编排步骤中,收到了异常:

The input is not a valid Base-64 string as it contains a non-base 64 character, more than two padding characters, or an illegal character among the padding characters.

该异常令人困惑,因为整个交互使用的是Base64Url编码,而该编码方式不包含填充字符。且该异常似乎发生在任何令牌声明验证之前——我曾故意在技术配置文件的<Item Key="IdTokenAudience" />元素中设置错误值,以测试流程进度,结果依然抛出该异常。

Application Insights 输出日志片段

{
  "Kind": "Transition",
  "Content": {
    "EventName": "GetClaims",
    "StateName": "AwaitingNextStep"
  }
},
{
  "Kind": "Predicate",
  "Content": "Web.TPEngine.StateMachineHandlers.NoOpHandler"
},
{
  "Kind": "HandlerResult",
  "Content": {
    "Result": true,
    "Statebag": {
      "MACHSTATE": {
        "c": "2023-07-17T14:46:56.4499692Z",
        "k": "MACHSTATE",
        "v": "AwaitingNextStep",
        "p": true
      }
    },
    "PredicateResult": "True"
  }
},
{
  "Kind": "Action",
  "Content": "Web.TPEngine.StateMachineHandlers.GetRelyingPartyInputClaimsHandler"
},
{
  "Kind": "FatalException",
  "Content": {
    "Time": "2:46 PM",
    "Exception": {
      "Kind": "Handled",
      "HResult": "80131537",
      "Message": "The input is not a valid Base-64 string as it contains a non-base 64 character, more than two padding characters, or an illegal character among the padding characters. ",
      "Data": {}
    }
  }
}

技术配置文件代码

<ClaimsProvider>
  <DisplayName>My ID Token Hint ClaimsProvider</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="IdTokenHint_ExtractClaims">
      <DisplayName> My ID Token Hint TechnicalProfile</DisplayName>
      <Protocol Name="None" />
      <Metadata>
      
        <!--Sample action required: replace with your endpoint location -->
        <Item Key="METADATA">https://lslscub2capp.azurewebsites.net/.well-known/openid-configuration</Item>

        <Item Key="IdTokenAudience">https://lslearnb2c.b2clogin.com/</Item>
        <!-- <Item Key="issuer">your_optional_token_issuer_override</Item> -->
      </Metadata>
      <OutputClaims>
        <!--Sample: Read the email cliam from the id_token_hint-->
        <OutputClaim ClaimTypeReferenceId="email" />  
      </OutputClaims>
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

内容的提问来源于stack exchange,提问作者lsuarez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 02:14:57