You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自定义Azure AD B2C的TrustFrameworkExtensions.xml策略

自定义Azure AD B2C TrustFrameworkExtensions.xml生成指定格式JWT

1. 定义自定义声明结构

在TrustFrameworkExtensions.xml的<ClaimsSchema>节点下,添加需要的基础声明和嵌套对象声明:

<ClaimsSchema>
  <!-- 声明姓、名字段 -->
  <ClaimType Id="lname">
    <DisplayName>姓氏</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
  <ClaimType Id="fname">
    <DisplayName>名字</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
</ClaimsSchema>

2. 配置JWT签发器的输出映射

找到负责签发JWT的<TechnicalProfile Id="JwtIssuer">节点,在<OutputClaims>中添加标准声明和自定义嵌套字段的映射,通过点语法实现JSON嵌套结构:

<TechnicalProfile Id="JwtIssuer">
  <OutputClaims>
    <!-- 保留原有标准声明映射 -->
    <OutputClaim ClaimTypeReferenceId="issuer" PartnerClaimType="iss" />
    <OutputClaim ClaimTypeReferenceId="sub" PartnerClaimType="sub" />
    <OutputClaim ClaimTypeReferenceId="audience" PartnerClaimType="aud" />
    <OutputClaim ClaimTypeReferenceId="expirationDateTime" PartnerClaimType="exp" />
    <OutputClaim ClaimTypeReferenceId="acr" PartnerClaimType="acr" />
    <OutputClaim ClaimTypeReferenceId="nonce" PartnerClaimType="nonce" />
    <OutputClaim ClaimTypeReferenceId="issuedAtDateTime" PartnerClaimType="iat" />
    <OutputClaim ClaimTypeReferenceId="authTime" PartnerClaimType="auth_time" />
    <OutputClaim ClaimTypeReferenceId="identityProvider" PartnerClaimType="idp" />
    <OutputClaim ClaimTypeReferenceId="tenantId" PartnerClaimType="tid" />

    <!-- 添加自定义嵌套字段映射,自动生成test对象 -->
    <OutputClaim ClaimTypeReferenceId="fname" PartnerClaimType="test.fname" />
    <OutputClaim ClaimTypeReferenceId="lname" PartnerClaimType="test.lname" />
  </OutputClaims>
</TechnicalProfile>

3. 确保声明数据被正确获取

如果fname和lname来自Azure AD B2C用户存储,需要在读取用户信息的技术配置(如<TechnicalProfile Id="AAD-UserReadUsingObjectId">)中添加输出声明,确保能获取到对应数据:

<TechnicalProfile Id="AAD-UserReadUsingObjectId">
  <OutputClaims>
    <!-- 原有输出声明 -->
    <OutputClaim ClaimTypeReferenceId="objectId" />
    <OutputClaim ClaimTypeReferenceId="displayName" />
    <!-- 映射用户存储中的姓和名 -->
    <OutputClaim ClaimTypeReferenceId="fname" PartnerClaimType="givenName" />
    <OutputClaim ClaimTypeReferenceId="lname" PartnerClaimType="surname" />
  </OutputClaims>
</TechnicalProfile>

4. 更新依赖方的输出声明

在<RelyingParty>节点的<TechnicalProfile Id="PolicyProfile">中,声明需要输出的自定义字段:

<RelyingParty>
  <DefaultUserJourney ReferenceId="SignUpOrSignIn" />
  <TechnicalProfile Id="PolicyProfile">
    <DisplayName>PolicyProfile</DisplayName>
    <Protocol Name="OpenIdConnect" />
    <OutputClaims>
      <!-- 标准声明 -->
      <OutputClaim ClaimTypeReferenceId="issuer" />
      <OutputClaim ClaimTypeReferenceId="sub" />
      <!-- 自定义声明 -->
      <OutputClaim ClaimTypeReferenceId="fname" />
      <OutputClaim ClaimTypeReferenceId="lname" />
    </OutputClaims>
    <SubjectNamingInfo ClaimType="sub" />
  </TechnicalProfile>
</RelyingParty>

关键注意事项

  • 嵌套JSON对象通过PartnerClaimType的点语法(如test.fname)自动生成,无需额外定义对象类型声明。
  • 若使用自定义用户属性,需先在Azure AD B2C租户中创建对应属性,再在<ClaimsSchema>中完成映射。
  • 配置完成后需上传策略并测试验证JWT格式是否符合预期。

内容的提问来源于stack exchange,提问作者Thanapon Makmesup

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 21:32:35