Azure B2C自断言页面忘记密码链接不显示问题排查
解决B2C自断言页面不显示忘记密码链接的问题
问题核心是你当前把ClaimsProviderSelection和ClaimsExchange放在同一个编排步骤里,而自断言技术配置文件默认不会渲染这类选择链接。以下是具体修复方案:
1. 拆分编排步骤结构
将原有的第一步拆分为两个独立步骤:一个专门用于渲染忘记密码链接,另一个执行邮箱验证的自断言流程。调整后的UserJourneys配置如下:
<UserJourneys> <UserJourney Id="SignIn"> <OrchestrationSteps> <!-- 第一步:渲染忘记密码链接 --> <OrchestrationStep Order="1" Type="ClaimsProviderSelection"> <ClaimsProviderSelections> <ClaimsProviderSelection TargetClaimsExchangeId="ForgotPasswordExchange" /> </ClaimsProviderSelections> </OrchestrationStep> <!-- 第二步:执行邮箱验证的自断言流程 --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="ValidateAccount" TechnicalProfileReferenceId="SelfAsserted-LocalAccountLookup" /> </ClaimsExchanges> </OrchestrationStep> <!-- 第三步:处理忘记密码流程(仅当未获取到objectId时执行) --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" /> </ClaimsExchanges> </OrchestrationStep> <!--Issue an access token--> <OrchestrationStep Order="4" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney> </UserJourneys>
2. 确认自断言技术配置文件的内容定义
检查SelfAsserted-LocalAccountLookup技术配置文件,确保它引用的内容定义支持渲染辅助链接:
<TechnicalProfile Id="SelfAsserted-LocalAccountLookup"> <DisplayName>Local Account Lookup</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item> <Item Key="IncludeClaimResolvingInClaimsHandling">true</Item> </Metadata> <!-- 其他配置项 --> </TechnicalProfile>
api.selfasserted是默认支持渲染忘记密码等辅助链接的内容定义模板,确保这个引用正确。
为什么这样改?
ClaimsProviderSelection类型的步骤专门负责渲染身份操作链接(比如忘记密码),必须单独设置才能让页面识别并显示这些链接。- 原配置将链接渲染和自断言流程放在同一步骤,导致自断言页面忽略了链接渲染逻辑。
- 拆分后,第一步先渲染链接,第二步执行邮箱验证,既满足新的登录旅程需求,又保留了忘记密码入口。
内容的提问来源于stack exchange,提问作者Bnd10706
相关产品推荐
相关产品推荐

