如何自定义Azure AD B2C的TrustFrameworkExtensions.xml策略
自定义Azure AD B2C TrustFrameworkExtensions.xml生成指定格式JWT
1. 定义自定义声明结构
在TrustFrameworkExtensions.xml的<ClaimsSchema>节点下,添加需要的基础声明和嵌套对象声明:
<ClaimsSchema> <!-- 声明姓、名字段 --> <ClaimType Id="lname"> <DisplayName>姓氏</DisplayName> <DataType>string</DataType> </ClaimType> <ClaimType Id="fname"> <DisplayName>名字</DisplayName> <DataType>string</DataType> </ClaimType> </ClaimsSchema>
2. 配置JWT签发器的输出映射
找到负责签发JWT的<TechnicalProfile Id="JwtIssuer">节点,在<OutputClaims>中添加标准声明和自定义嵌套字段的映射,通过点语法实现JSON嵌套结构:
<TechnicalProfile Id="JwtIssuer"> <OutputClaims> <!-- 保留原有标准声明映射 --> <OutputClaim ClaimTypeReferenceId="issuer" PartnerClaimType="iss" /> <OutputClaim ClaimTypeReferenceId="sub" PartnerClaimType="sub" /> <OutputClaim ClaimTypeReferenceId="audience" PartnerClaimType="aud" /> <OutputClaim ClaimTypeReferenceId="expirationDateTime" PartnerClaimType="exp" /> <OutputClaim ClaimTypeReferenceId="acr" PartnerClaimType="acr" /> <OutputClaim ClaimTypeReferenceId="nonce" PartnerClaimType="nonce" /> <OutputClaim ClaimTypeReferenceId="issuedAtDateTime" PartnerClaimType="iat" /> <OutputClaim ClaimTypeReferenceId="authTime" PartnerClaimType="auth_time" /> <OutputClaim ClaimTypeReferenceId="identityProvider" PartnerClaimType="idp" /> <OutputClaim ClaimTypeReferenceId="tenantId" PartnerClaimType="tid" /> <!-- 添加自定义嵌套字段映射,自动生成test对象 --> <OutputClaim ClaimTypeReferenceId="fname" PartnerClaimType="test.fname" /> <OutputClaim ClaimTypeReferenceId="lname" PartnerClaimType="test.lname" /> </OutputClaims> </TechnicalProfile>
3. 确保声明数据被正确获取
如果fname和lname来自Azure AD B2C用户存储,需要在读取用户信息的技术配置(如<TechnicalProfile Id="AAD-UserReadUsingObjectId">)中添加输出声明,确保能获取到对应数据:
<TechnicalProfile Id="AAD-UserReadUsingObjectId"> <OutputClaims> <!-- 原有输出声明 --> <OutputClaim ClaimTypeReferenceId="objectId" /> <OutputClaim ClaimTypeReferenceId="displayName" /> <!-- 映射用户存储中的姓和名 --> <OutputClaim ClaimTypeReferenceId="fname" PartnerClaimType="givenName" /> <OutputClaim ClaimTypeReferenceId="lname" PartnerClaimType="surname" /> </OutputClaims> </TechnicalProfile>
4. 更新依赖方的输出声明
在<RelyingParty>节点的<TechnicalProfile Id="PolicyProfile">中,声明需要输出的自定义字段:
<RelyingParty> <DefaultUserJourney ReferenceId="SignUpOrSignIn" /> <TechnicalProfile Id="PolicyProfile"> <DisplayName>PolicyProfile</DisplayName> <Protocol Name="OpenIdConnect" /> <OutputClaims> <!-- 标准声明 --> <OutputClaim ClaimTypeReferenceId="issuer" /> <OutputClaim ClaimTypeReferenceId="sub" /> <!-- 自定义声明 --> <OutputClaim ClaimTypeReferenceId="fname" /> <OutputClaim ClaimTypeReferenceId="lname" /> </OutputClaims> <SubjectNamingInfo ClaimType="sub" /> </TechnicalProfile> </RelyingParty>
关键注意事项
- 嵌套JSON对象通过
PartnerClaimType的点语法(如test.fname)自动生成,无需额外定义对象类型声明。 - 若使用自定义用户属性,需先在Azure AD B2C租户中创建对应属性,再在
<ClaimsSchema>中完成映射。 - 配置完成后需上传策略并测试验证JWT格式是否符合预期。
内容的提问来源于stack exchange,提问作者Thanapon Makmesup
相关产品推荐
相关产品推荐

