Azure Active Directory B2C 手机号注册/登录的特定国家/地区限制
限制Azure AD B2C手机号OTP登录的国家/地区范围
Azure AD B2C原生没有提供直接配置允许手机号国家/地区的选项,要实现这个需求必须通过**自定义策略(Custom Policy)**来完成,以下是具体实现步骤:
1. 定义允许的国家/地区代码列表
在自定义策略的<ClaimsSchema>节点下,添加一个字符串集合类型的声明,用来存储你允许的国家/地区拨号代码:
<ClaimsSchema> <ClaimType Id="allowedCountryCodes"> <DisplayName>Allowed Country Codes</DisplayName> <DataType>stringCollection</DataType> <AdminHelpText>List of allowed country calling codes, e.g., "+86", "+1"</AdminHelpText> <Restriction> </think_never_used_51bce0c785ca2f68081bfa7d91973934> 我需要继续完成这个回答,之前的内容被截断了。现在补充完整: --- # 限制Azure AD B2C手机号OTP登录的国家/地区范围 Azure AD B2C原生没有提供直接配置允许手机号国家/地区的选项,要实现这个需求必须通过**自定义策略(Custom Policy)**来完成,以下是具体实现步骤: ## 1. 定义允许的国家/地区代码列表 在自定义策略的`<ClaimsSchema>`节点下,添加一个字符串集合类型的声明,用来存储你允许的国家/地区拨号代码: ```xml <ClaimsSchema> <ClaimType Id="allowedCountryCodes"> <DisplayName>Allowed Country Codes</DisplayName> <DataType>stringCollection</DataType> <AdminHelpText>List of allowed country calling codes, e.g., "+86", "+1"</AdminHelpText> <Restriction> <Enumeration Text="+86" Value="+86" /> <Enumeration Text="+1" Value="+1" /> <!-- 添加更多你需要允许的国家代码 --> </Restriction> </ClaimType> </ClaimsSchema>
2. 创建验证手机号国家代码的技术配置文件
在<ClaimsProviders>节点下,添加验证用的技术配置文件和对应的声明转换规则,检查用户输入的手机号前缀是否在允许列表中:
<ClaimsProviders> <ClaimsProvider> <DisplayName>Validation Claims Provider</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="ValidatePhoneCountry"> <DisplayName>Validate Phone Country Code</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <InputClaims> <InputClaim ClaimTypeReferenceId="phoneNumber" /> <InputClaim ClaimTypeReferenceId="allowedCountryCodes" /> </InputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CheckPhoneCountryCode" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> <ClaimsProvider> <DisplayName>Error Provider</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="ThrowPhoneCountryErrorProfile"> <DisplayName>Throw Phone Country Not Allowed Error</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="ThrowPhoneCountryNotAllowedError" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> </ClaimsProviders> <!-- 声明转换规则 --> <ClaimsTransformations> <ClaimsTransformation Id="CheckPhoneCountryCode" TransformationMethod="StringCollectionContains"> <InputClaims> <InputClaim ClaimTypeReferenceId="phoneNumber" TransformationClaimType="inputString" /> <InputClaim ClaimTypeReferenceId="allowedCountryCodes" TransformationClaimType="collection" /> </InputClaims> <InputParameters> <InputParameter Id="containsMode" DataType="string" Value="Prefix" /> <InputParameter Id="ignoreCase" DataType="boolean" Value="true" /> </InputParameters> <OutputClaims> <OutputClaim ClaimTypeReferenceId="isPhoneCountryAllowed" TransformationClaimType="outputClaim" /> </OutputClaims> </ClaimsTransformation> <ClaimsTransformation Id="ThrowPhoneCountryNotAllowedError" TransformationMethod="ThrowClaimValueError"> <InputClaims> <InputClaim ClaimTypeReferenceId="isPhoneCountryAllowed" TransformationClaimType="claimValue" /> </InputClaims> <InputParameters> <InputParameter Id="errorMessage" DataType="string" Value="该手机号所属国家/地区不支持,请更换其他号码重试。" /> <InputParameter Id="claimValueToMatch" DataType="boolean" Value="false" /> </InputParameters> </ClaimsTransformation> </ClaimsTransformations>
3. 将验证步骤集成到手机号登录用户旅程
找到你用于手机号OTP登录的用户旅程(比如SignUpOrSignInWithPhone),在用户输入手机号后的步骤中插入验证逻辑:
<UserJourneys> <UserJourney Id="SignUpOrSignInWithPhone"> <OrchestrationSteps> <!-- 步骤1:显示手机号输入界面 --> <OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="PhoneFactor-Input" TechnicalProfileReferenceId="PhoneFactor-Input" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤2:验证手机号国家代码 --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="ValidatePhoneCountryExchange" TechnicalProfileReferenceId="ValidatePhoneCountry" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤3:如果国家代码不允许,抛出错误 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>isPhoneCountryAllowed</Value> <Value>false</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="ThrowPhoneCountryError" TechnicalProfileReferenceId="ThrowPhoneCountryErrorProfile" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤4:国家代码允许则继续OTP验证流程 --> <OrchestrationStep Order="4" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>isPhoneCountryAllowed</Value> <Value>false</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="PhoneFactor-Verify" TechnicalProfileReferenceId="PhoneFactor-InputOrVerify" /> </ClaimsExchanges> </OrchestrationStep> <!-- 后续流程步骤... --> </OrchestrationSteps> </UserJourney> </UserJourneys>
关键说明
- 确保用户输入的手机号包含国家代码前缀(如
+8613xxxxxxxxx),如果登录界面默认不带前缀,需先让用户选择国家/地区,再拼接前缀后进行验证。 - 可根据业务需求调整
allowedCountryCodes中的枚举值,添加或移除支持的国家代码。 - 错误消息可通过修改
ThrowPhoneCountryNotAllowedError中的errorMessage参数自定义。
内容的提问来源于stack exchange,提问作者rid00z
相关产品推荐
相关产品推荐

