You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C自定义策略:AAD SSPR邮箱验证按钮及输入框缺失问题

Azure B2C自定义策略邮箱验证配置问题分析

核心问题原因

直接将AAD SSPR的SendCode和VerifyCode作为Self Asserted技术配置的验证技术配置,存在以下关键遗漏:

  • 缺少验证码输入框的渲染配置:你的VerifyEmailAddress技术配置的OutputClaims里只包含了signInNames.emailAddress,没有添加verificationCode字段,页面自然不会渲染验证码输入框。
  • 验证流程逻辑不匹配:Self Asserted的验证技术配置是点击Continue后一次性执行所有验证步骤,点击按钮时会先调用AadSspr-SendCode发送验证码,紧接着就调用AadSspr-VerifyCode验证,但此时用户根本没机会输入验证码,直接导致流程卡死。而DisplayControl的VerificationControl是专门为分步验证设计的,自带了Send/Verify按钮的交互逻辑,能分别触发发送和验证操作。

修正方案

如果你不想使用DisplayControl,需要将验证拆分为两个独立的Self Asserted步骤:

步骤1:发送验证码

创建仅负责发送验证码的Self Asserted技术配置:

<TechnicalProfile Id="SendVerificationCode">
  <DisplayName>Send Verification Code</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
    <Item Key="setting.showContinueButton">true</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInNames.emailAddress" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="signInNames.emailAddress" Required="true" />
  </OutputClaims>
  <ValidationTechnicalProfiles>
    <ValidationTechnicalProfile ReferenceId="AadSspr-SendCode" ContinueOnError="false" />
  </ValidationTechnicalProfiles>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

步骤2:验证验证码

创建负责输入并验证验证码的Self Asserted技术配置:

<TechnicalProfile Id="VerifyVerificationCode">
  <DisplayName>Verify Verification Code</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
    <Item Key="setting.showContinueButton">true</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInNames.emailAddress" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="verificationCode" Required="true" />
  </OutputClaims>
  <ValidationTechnicalProfiles>
    <ValidationTechnicalProfile ReferenceId="AadSspr-VerifyCode" ContinueOnError="false" />
  </ValidationTechnicalProfiles>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

在用户旅程中调用这两个步骤

将这两个技术配置按顺序添加到用户旅程的Orchestration Step中:

<OrchestrationStep Order="X" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="SendCodeExchange" TechnicalProfileReferenceId="SendVerificationCode" />
  </ClaimsExchanges>
</OrchestrationStep>
<OrchestrationStep Order="X+1" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="VerifyCodeExchange" TechnicalProfileReferenceId="VerifyVerificationCode" />
  </ClaimsExchanges>
</OrchestrationStep>

总结

使用DisplayControl的VerificationControl是Azure B2C官方推荐的实现邮箱验证的方式,因为它原生支持分步交互逻辑。如果非要拆分步骤,就需要分成两个独立的Self Asserted页面,分别处理发送和验证操作。

内容的提问来源于stack exchange,提问作者SilviuM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 17:53:17