基于邮箱地址的登录/注册流程跳转:SignIn/SignUp技术配置文件调用异常问题排查
解决B2C中ValidationTechnicalProfile的ContinueOnError不生效问题
我一眼就发现问题的核心了——你的AAD-UserReadEmailAddress技术配置文件里设置了<Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>,这个配置的优先级高于ContinueOnError="true",它会强制触发错误抛出,直接绕过了“继续执行”的逻辑。
解决方案
把RaiseErrorIfClaimsPrincipalDoesNotExist的值改为false,这样当用户不存在时,AAD不会主动抛出错误,ContinueOnError="true"的配置就能正常生效,流程会继续向下执行(比如跳转至注册流程)。修改后的完整配置如下:
<TechnicalProfile Id="AAD-UserReadEmailAddress"> <Metadata> <Item Key="Operation">Read</Item> <!-- 关键修改:将此处设为false --> <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">false</Item> <Item Key="UserMessageIfClaimsPrincipalDoesNotExist">An account could not be found for the provided user ID.</Item> </Metadata> <IncludeInSso>false</IncludeInSso> <InputClaims> <InputClaim ClaimTypeReferenceId="email" PartnerClaimType="signInNames.emailAddress" Required="true" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="objectId" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="localAccountAuthentication" /> <OutputClaim ClaimTypeReferenceId="userPrincipalName" /> <OutputClaim ClaimTypeReferenceId="displayName" /> <OutputClaim ClaimTypeReferenceId="otherMails" /> <OutputClaim ClaimTypeReferenceId="signInNames.emailAddress" /> </OutputClaims> <IncludeTechnicalProfile ReferenceId="AAD-Common" /> </TechnicalProfile>
额外说明
- 当
RaiseErrorIfClaimsPrincipalDoesNotExist设为false时,若用户不存在,该读取操作只会返回空的输出声明(比如objectId会为空),不会抛出错误。此时ContinueOnError="true"的配置才会生效,你可以在后续流程中通过判断objectId是否为空,来决定触发登录还是注册逻辑。 - 如果你需要保留“账户不存在”的提示,可以在后续自断言技术配置文件中添加逻辑,检查
objectId是否为空,再显示对应的错误信息。
内容的提问来源于stack exchange,提问作者Rohit Prasad
相关产品推荐
相关产品推荐

