Azure AD B2C自定义策略:TOTP与SendGrid集成后注册二维码不显示及Claim缺失报错
问题诊断与修复方案
核心原因
注册流程里未初始化或传递totpIdentifier声明,导致CreateUriLabel这个ClaimsTransformation找不到该声明,触发PolicyException,进而二维码页面加载失败;而登录流程中该声明已正常生成或传递,因此运行无异常。
具体修复步骤
- 检查策略的
<BuildingBlocks><ClaimsSchema>节点,若未定义totpIdentifier声明,直接添加以下代码:<ClaimType Id="totpIdentifier"> <DisplayName>TOTP Identifier</DisplayName> <DataType>string</DataType> <UserHelpText>TOTP认证的唯一标识</UserHelpText> </ClaimType> - 在注册流程的用户旅程中,需在调用
CreateUriLabel转换前生成totpIdentifier的值。通常用用户的Object ID与租户ID组合生成,示例转换代码如下:<ClaimsTransformation Id="GenerateTotpIdentifier" TransformationMethod="FormatStringMultipleClaims"> <InputClaims> <InputClaim ClaimTypeReferenceId="objectId" TransformationClaimType="inputClaim1" /> <InputClaim ClaimTypeReferenceId="tenantId" TransformationClaimType="inputClaim2" /> </InputClaims> <InputParameters> <InputParameter Id="stringFormat" Value="{0}@{1}" /> </InputParameters> <OutputClaims> <OutputClaim ClaimTypeReferenceId="totpIdentifier" TransformationClaimType="outputClaim" /> </OutputClaims> </ClaimsTransformation> - 将上述
GenerateTotpIdentifier转换添加到注册流程对应的<TechnicalProfile>或<OrchestrationStep>中,确保在执行CreateUriLabel前完成totpIdentifier的赋值。 - 核对注册流程的用户旅程,确认展示二维码的步骤中,
totpIdentifier已正确传递到对应的显示控件或技术配置里。
验证方式
- 重新上传修改后的扩展策略文件
- 测试注册流程,确认二维码页面正常显示
- 查看Application Insights,确认
PolicyException不再出现
内容的提问来源于stack exchange,提问作者momin naveed
相关产品推荐
相关产品推荐

