Azure B2C自定义策略:首次登录强制重置密码及完善用户信息
Azure B2C自定义策略解决方案
核心需求实现逻辑
1. 首次登录强制重置密码+补充信息
- 用自定义属性区分新老用户:创建
extension_IsFirstLogin布尔属性,Graph API创建用户时设为true,同时开启passwordProfile.forceChangePasswordNextLogin。 - 用户旅程中添加分支判断:登录成功后检查
extension_IsFirstLogin,若为true,先执行密码重置,再收集姓名信息,最后更新用户属性并将该字段设为false。
2. 单一用户旅程整合功能
在用户旅程中包含SignUpOrSignIn、ForgotPassword分支,通过前置条件控制不同用户的流程走向:老用户直接登录,新用户走首次登录流程,忘记密码用户走重置分支。
现有问题解决
问题1:忘记密码链接失效+无法收集姓名信息
修复忘记密码链接
- 定义
ForgotPassword用户旅程,包含邮箱验证、密码重置步骤:
<UserJourneys> <UserJourney Id="ForgotPassword"> <OrchestrationSteps> <OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="PasswordResetUsingEmailAddressExchange" TechnicalProfileReferenceId="LocalAccountDiscoveryUsingEmailAddress" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="NewCredentials" TechnicalProfileReferenceId="LocalAccountWritePasswordUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="4" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney> </UserJourneys>
- 在登录页面的HTML中配置链接跳转逻辑:
<a href="javascript:redirectToForgotPassword()">Forgot your password?</a> <script> function redirectToForgotPassword() { const searchParams = new URLSearchParams(window.location.search); searchParams.set('p', 'B2C_1A_forgotpassword'); window.location.href = `${window.location.origin}/oauth2/v2.0/authorize?${searchParams.toString()}`; } </script>
在重置流程中收集姓名
在ForgotPassword用户旅程的密码重置步骤后,添加判断步骤:若用户缺少givenName/surname,触发信息收集页面:
<OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimExists" ExecuteActionsIf="true"> <Value>givenName</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimExists" ExecuteActionsIf="true"> <Value>surname</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="CollectProfileInfoExchange" TechnicalProfileReferenceId="SelfAsserted-CollectProfileInfo" /> </ClaimsExchanges> </OrchestrationStep>
同时创建信息收集的技术配置:
<TechnicalProfile Id="SelfAsserted-CollectProfileInfo"> <DisplayName>Collect Profile Information</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="objectId" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="givenName" Required="true" /> <OutputClaim ClaimTypeReferenceId="surname" Required="true" /> <OutputClaim ClaimTypeReferenceId="displayName" Required="true" /> </OutputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" /> </TechnicalProfile>
问题2:嵌入式密码重置的Facebook-Auth及AlternativeSecurityId错误
由于使用本地账户starter pack,需移除所有社交账户相关配置:
- 删除
ClaimsProviders中所有Facebook相关节点,包括Facebook-OAUTH技术配置。 - 删除所有依赖
AlternativeSecurityId的ClaimsTransformation和验证技术配置(如社交账户身份转换逻辑)。 - 检查用户旅程,移除所有社交账户登录/注册的
OrchestrationStep,仅保留本地账户流程。
内容的提问来源于stack exchange,提问作者The Last Stark
相关产品推荐
相关产品推荐

