Azure AD B2C自定义策略:安全存储Client ID和密钥并用于REST API
在Azure AD B2C自定义策略中安全存储并读取Client ID和Client Secret到REST API输入声明
步骤1:在Azure B2C租户中创建策略密钥
- 登录Azure门户,进入目标B2C租户,找到Identity Experience Framework
- 进入策略密钥页面,点击添加按钮
- 分别创建两个密钥:
- 存储Client ID:类型选择字符串,输入你的Client ID值,命名为
B2CAppClientId(可自定义,需和后续配置一致) - 存储Client Secret:类型选择字符串(密钥),输入Client Secret值,命名为
B2CAppClientSecret
- 存储Client ID:类型选择字符串,输入你的Client ID值,命名为
- 确认两个密钥状态为已启用
步骤2:在自定义策略中声明密钥引用与对应声明类型
打开自定义策略的扩展文件(如TrustFrameworkExtensions.xml),做以下修改:
- 在
<BuildingBlocks>的<ClaimsSchema>节点下添加声明类型定义:
<ClaimsSchema> <ClaimType Id="client_id"> <DisplayName>Client ID</DisplayName> <DataType>string</DataType> </ClaimType> <ClaimType Id="client_secret"> <DisplayName>Client Secret</DisplayName> <DataType>string</DataType> </ClaimType> </ClaimsSchema>
- 在
<ClaimsProviders>节点下添加用于读取密钥的技术配置文件:
<ClaimsProvider> <DisplayName>Key References</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="GetClientCredentials"> <DisplayName>Retrieve Client Credentials from Policy Keys</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <OutputClaims> <OutputClaim ClaimTypeReferenceId="client_id" DefaultValue="{Settings:B2CAppClientId}" /> <OutputClaim ClaimTypeReferenceId="client_secret" DefaultValue="{Settings:B2CAppClientSecret}" /> </OutputClaims> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
步骤3:修改REST API技术配置文件,引用密钥声明
找到调用token端点的REST API技术配置文件,更新<InputClaims>节点,将密钥声明作为表单参数传入:
<TechnicalProfile Id="REST-CallTokenEndpoint"> <DisplayName>Call Token Endpoint</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://{tenant}.b2clogin.com/{tenant}.onmicrosoft.com/B2C_1A_SIGNUP_SIGNIN/oauth2/v2.0/token</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Form</Item> </Metadata> <InputClaims> <!-- 添加其他必要的表单参数,如grant_type、scope等 --> <InputClaim ClaimTypeReferenceId="client_id" PartnerClaimType="client_id" /> <InputClaim ClaimTypeReferenceId="client_secret" PartnerClaimType="client_secret" /> </InputClaims> <!-- 按需配置OutputClaims、UseTechnicalProfileForSessionManagement等节点 --> </TechnicalProfile>
步骤4:在用户旅程中添加密钥检索步骤
打开用户旅程文件(如SignUpOrSignin.xml),在调用REST API的步骤前,先执行密钥检索的技术配置文件,确保声明被加载:
<UserJourney Id="SignUpOrSignIn"> <OrchestrationSteps> <!-- 保留原有登录/注册等步骤 --> <OrchestrationStep Order="X" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="RetrieveClientCredentials" TechnicalProfileReferenceId="GetClientCredentials" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="X+1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="CallTokenEndpoint" TechnicalProfileReferenceId="REST-CallTokenEndpoint" /> </ClaimsExchanges> </OrchestrationStep> <!-- 保留后续流程步骤 --> </OrchestrationSteps> </UserJourney>
注意事项
- 策略密钥名称与XML中
{Settings:XXX}的XXX需完全一致,大小写敏感 - Client Secret存储为策略密钥后会被加密,不会在策略文件中暴露明文
- 若出现声明未加载的问题,可启用B2C策略日志排查
内容的提问来源于stack exchange,提问作者Rajendra Thorat
相关产品推荐
相关产品推荐

