You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略:安全存储Client ID和密钥并用于REST API

在Azure AD B2C自定义策略中安全存储并读取Client ID和Client Secret到REST API输入声明

步骤1:在Azure B2C租户中创建策略密钥

  • 登录Azure门户,进入目标B2C租户,找到Identity Experience Framework
  • 进入策略密钥页面,点击添加按钮
  • 分别创建两个密钥:
    • 存储Client ID:类型选择字符串,输入你的Client ID值,命名为B2CAppClientId(可自定义,需和后续配置一致)
    • 存储Client Secret:类型选择字符串(密钥),输入Client Secret值,命名为B2CAppClientSecret
  • 确认两个密钥状态为已启用

步骤2:在自定义策略中声明密钥引用与对应声明类型

打开自定义策略的扩展文件(如TrustFrameworkExtensions.xml),做以下修改:

  1. 在<BuildingBlocks>的<ClaimsSchema>节点下添加声明类型定义:
<ClaimsSchema>
  <ClaimType Id="client_id">
    <DisplayName>Client ID</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
  <ClaimType Id="client_secret">
    <DisplayName>Client Secret</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
</ClaimsSchema>
  1. 在<ClaimsProviders>节点下添加用于读取密钥的技术配置文件:
<ClaimsProvider>
  <DisplayName>Key References</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="GetClientCredentials">
      <DisplayName>Retrieve Client Credentials from Policy Keys</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="client_id" DefaultValue="{Settings:B2CAppClientId}" />
        <OutputClaim ClaimTypeReferenceId="client_secret" DefaultValue="{Settings:B2CAppClientSecret}" />
      </OutputClaims>
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

步骤3:修改REST API技术配置文件,引用密钥声明

找到调用token端点的REST API技术配置文件,更新<InputClaims>节点,将密钥声明作为表单参数传入:

<TechnicalProfile Id="REST-CallTokenEndpoint">
  <DisplayName>Call Token Endpoint</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://{tenant}.b2clogin.com/{tenant}.onmicrosoft.com/B2C_1A_SIGNUP_SIGNIN/oauth2/v2.0/token</Item>
    <Item Key="AuthenticationType">None</Item>
    <Item Key="SendClaimsIn">Form</Item>
  </Metadata>
  <InputClaims>
    <!-- 添加其他必要的表单参数,如grant_type、scope等 -->
    <InputClaim ClaimTypeReferenceId="client_id" PartnerClaimType="client_id" />
    <InputClaim ClaimTypeReferenceId="client_secret" PartnerClaimType="client_secret" />
  </InputClaims>
  <!-- 按需配置OutputClaims、UseTechnicalProfileForSessionManagement等节点 -->
</TechnicalProfile>

步骤4:在用户旅程中添加密钥检索步骤

打开用户旅程文件(如SignUpOrSignin.xml),在调用REST API的步骤前,先执行密钥检索的技术配置文件,确保声明被加载:

<UserJourney Id="SignUpOrSignIn">
  <OrchestrationSteps>
    <!-- 保留原有登录/注册等步骤 -->
    <OrchestrationStep Order="X" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="RetrieveClientCredentials" TechnicalProfileReferenceId="GetClientCredentials" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="X+1" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="CallTokenEndpoint" TechnicalProfileReferenceId="REST-CallTokenEndpoint" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- 保留后续流程步骤 -->
  </OrchestrationSteps>
</UserJourney>

注意事项

  • 策略密钥名称与XML中{Settings:XXX}的XXX需完全一致,大小写敏感
  • Client Secret存储为策略密钥后会被加密,不会在策略文件中暴露明文
  • 若出现声明未加载的问题,可启用B2C策略日志排查

内容的提问来源于stack exchange,提问作者Rajendra Thorat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 22:00:14