Azure B2C电话验证页面限流提示未显示问题咨询
我们有一个仅支持注册的自定义策略,包含收集MFA电话号码的电话验证步骤,页面与官方示例基本一致。使用multifactor:1.2.5数据URI,已按照本地化字符串ID文档添加了error_tryagain、error_sms_throttled、error_phone_throttled、error_throttled、error_incorrect_code等错误本地化条目。
多次点击重发SMS验证码链接后,短信停止发送,Azure门户用户历史中显示错误提示:“当前请求过多,请稍后重试”,但该限流提示并未在页面上显示,而页面其他本地化功能均正常工作。请问是否遗漏了某些配置,或是该场景本就不会显示错误提示?
<!-- PhoneRegisterOrMFAPage --> <ContentDefinition Id="api.partners.phoneRegisterOrMFAPage"> <LoadUri>~/tenant/templates/AzureBlue/multifactor-1.0.0.cshtml</LoadUri> <RecoveryUri>~/common/default_page_error.html</RecoveryUri> <DataUri>urn:com:microsoft:aad:b2c:elements:contract:multifactor:1.2.5</DataUri> <Metadata> <Item Key="DisplayName">Multi-factor authentication page</Item> </Metadata> </ContentDefinition> <TechnicalProfile Id="PhoneRegisterOrMFAPage"> <DisplayName>PhoneFactor</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.partners.phoneRegisterOrMFAPage</Item> <!-- Setting the below to true, so the same profile can be used for phone MFA, or phone registration. Will avoid coming here when doing MFA and no phone --> <Item Key="ManualPhoneNumberEntryAllowed">true</Item> <Item Key="setting.authenticationMode">sms</Item> </Metadata> <InputClaimsTransformations> <InputClaimsTransformation ReferenceId="CreateUserIdForMFA" /> </InputClaimsTransformations> <InputClaims> <InputClaim ClaimTypeReferenceId="userIdForMFA" PartnerClaimType="UserId" /> <InputClaim ClaimTypeReferenceId="strongAuthenticationPhoneNumber" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="Verified.OfficePhone" /> <OutputClaim ClaimTypeReferenceId="newPhoneNumberEntered" PartnerClaimType="newPhoneNumberEntered" /> </OutputClaims> <IncludeTechnicalProfile ReferenceId="AAD-Common" /> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile> <LocalizedResources Id="api.partners.phoneRegisterOrMFAPage.en"> <LocalizedStrings> ... <LocalizedString ElementType="UxElement" StringId="error_tryagain">EN-The phone number you provided is busy or unavailable. Please check the number and try again.</LocalizedString> <LocalizedString ElementType="UxElement" StringId="error_sms_throttled">EN-You hit the limit on the number of text messages. Try again shortly.</LocalizedString> <LocalizedString ElementType="UxElement" StringId="error_phone_throttled">EN-You hit the limit on the number of call attempts. Try again shortly.</LocalizedString> <LocalizedString ElementType="UxElement" StringId="error_throttled">EN-You hit the limit on the number of verification attempts. Try again shortly.</LocalizedString> <LocalizedString ElementType="UxElement" StringId="error_incorrect_code">EN-The verification code you have entered does not match our records. Please try again, or request a new code.</LocalizedString> ... </LocalizedStrings> </LocalizedResources>
可能的原因及解决方案
1. 限流错误对应的字符串ID不匹配
Azure AD B2C针对SMS重发的高频限流,触发的错误字符串ID可能不是你当前配置的几个。除已配置条目外,需检查是否缺少:
error_too_many_attempts:部分版本MFA控件会用这个ID标识高频请求限流- 确认
error_sms_throttled是否对应重发SMS的限流场景(部分场景下该ID仅针对验证码验证次数过多,而非重发请求)
2. ContentDefinition版本不匹配
你的ContentDefinition中LoadUri使用multifactor-1.0.0.cshtml,但DataUri是multifactor:1.2.5,版本不一致可能导致控件无法识别新的错误字符串ID。建议更新LoadUri:
<LoadUri>~/tenant/templates/AzureBlue/multifactor-1.2.5.cshtml</LoadUri>
3. 未开启页面端限流提示
在PhoneRegisterOrMFAPage技术配置的Metadata中,添加元数据启用页面端限流提示:
<Item Key="setting.showThrottleErrors">true</Item>
4. 后端级限流未传递到前端
部分限流错误属于Azure AD B2C后端拦截,不会直接返回给前端页面。这种情况下需通过自定义策略的ClaimsTransformation或ValidationTechnicalProfile捕获错误,映射为前端可识别的消息。
内容的提问来源于stack exchange,提问作者fei0x

