You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C自定义策略:首次登录强制重置密码及完善用户信息

Azure B2C自定义策略解决方案

核心需求实现逻辑

1. 首次登录强制重置密码+补充信息

  • 用自定义属性区分新老用户:创建extension_IsFirstLogin布尔属性,Graph API创建用户时设为true,同时开启passwordProfile.forceChangePasswordNextLogin。
  • 用户旅程中添加分支判断:登录成功后检查extension_IsFirstLogin,若为true,先执行密码重置,再收集姓名信息,最后更新用户属性并将该字段设为false。

2. 单一用户旅程整合功能

在用户旅程中包含SignUpOrSignIn、ForgotPassword分支,通过前置条件控制不同用户的流程走向:老用户直接登录,新用户走首次登录流程,忘记密码用户走重置分支。


现有问题解决

问题1:忘记密码链接失效+无法收集姓名信息

修复忘记密码链接

  1. 定义ForgotPassword用户旅程,包含邮箱验证、密码重置步骤:
<UserJourneys>
  <UserJourney Id="ForgotPassword">
    <OrchestrationSteps>
      <OrchestrationStep Order="1" Type="ClaimsExchange">
        <ClaimsExchanges>
          <ClaimsExchange Id="PasswordResetUsingEmailAddressExchange" TechnicalProfileReferenceId="LocalAccountDiscoveryUsingEmailAddress" />
        </ClaimsExchanges>
      </OrchestrationStep>
      <OrchestrationStep Order="2" Type="ClaimsExchange">
        <ClaimsExchanges>
          <ClaimsExchange Id="NewCredentials" TechnicalProfileReferenceId="LocalAccountWritePasswordUsingObjectId" />
        </ClaimsExchanges>
      </OrchestrationStep>
      <OrchestrationStep Order="4" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
    </OrchestrationSteps>
    <ClientDefinition ReferenceId="DefaultWeb" />
  </UserJourney>
</UserJourneys>
  1. 在登录页面的HTML中配置链接跳转逻辑:
<a href="javascript:redirectToForgotPassword()">Forgot your password?</a>
<script>
function redirectToForgotPassword() {
  const searchParams = new URLSearchParams(window.location.search);
  searchParams.set('p', 'B2C_1A_forgotpassword');
  window.location.href = `${window.location.origin}/oauth2/v2.0/authorize?${searchParams.toString()}`;
}
</script>

在重置流程中收集姓名

在ForgotPassword用户旅程的密码重置步骤后,添加判断步骤:若用户缺少givenName/surname,触发信息收集页面:

<OrchestrationStep Order="3" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimExists" ExecuteActionsIf="true">
      <Value>givenName</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimExists" ExecuteActionsIf="true">
      <Value>surname</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="CollectProfileInfoExchange" TechnicalProfileReferenceId="SelfAsserted-CollectProfileInfo" />
  </ClaimsExchanges>
</OrchestrationStep>

同时创建信息收集的技术配置:

<TechnicalProfile Id="SelfAsserted-CollectProfileInfo">
  <DisplayName>Collect Profile Information</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="objectId" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="givenName" Required="true" />
    <OutputClaim ClaimTypeReferenceId="surname" Required="true" />
    <OutputClaim ClaimTypeReferenceId="displayName" Required="true" />
  </OutputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" />
</TechnicalProfile>

问题2:嵌入式密码重置的Facebook-Auth及AlternativeSecurityId错误

由于使用本地账户starter pack,需移除所有社交账户相关配置:

  1. 删除ClaimsProviders中所有Facebook相关节点,包括Facebook-OAUTH技术配置。
  2. 删除所有依赖AlternativeSecurityId的ClaimsTransformation和验证技术配置(如社交账户身份转换逻辑)。
  3. 检查用户旅程,移除所有社交账户登录/注册的OrchestrationStep,仅保留本地账户流程。

内容的提问来源于stack exchange,提问作者The Last Stark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 21:05:43