如何在Azure AD B2C自定义策略中跳过已登录用户的登录步骤
解决方案:已登录用户跳过编辑资料/重置密码的登录步骤
一、修改ProfileEdit用户旅程
原配置中步骤1和2为强制登录流程,我们需要添加会话检查逻辑,让已登录(持有有效会话)的用户直接跳过登录步骤,进入资料编辑环节。
修改后的完整ProfileEdit用户旅程配置:
<UserJourney Id="ProfileEdit"> <OrchestrationSteps> <!-- 步骤0:检查当前是否存在有效会话,若存在则直接获取用户objectId --> <OrchestrationStep Order="0" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="SessionRead" TechnicalProfileReferenceId="SM-SessionRead" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤1:身份提供商选择(仅未登录时执行) --> <OrchestrationStep Order="1" Type="ClaimsProviderSelection" ContentDefinitionReferenceId="api.idpselections"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsProviderSelections> <ClaimsProviderSelection TargetClaimsExchangeId="LocalAccountSigninEmailExchange" /> </ClaimsProviderSelections> </OrchestrationStep> <!-- 步骤2:本地账户登录(仅未登录时执行) --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤3:读取用户信息 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤4:编辑用户资料 --> <OrchestrationStep Order="4" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="B2CUserProfileUpdateExchange" TechnicalProfileReferenceId="SelfAsserted-ProfileUpdate" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤5:颁发令牌 --> <OrchestrationStep Order="5" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney>
关键逻辑说明:
- 步骤0:调用入门包默认包含的
SM-SessionRead技术配置读取当前会话,若会话有效则自动填充objectId声明;若已存在objectId(用户已登录),则直接跳过此步骤。 - 步骤1和2:通过前置条件检查
objectId是否存在,若存在则跳过登录流程,直接进入用户信息读取环节。
二、重置密码用户旅程的适配逻辑
对于PasswordReset这类重置密码的用户旅程,可复用完全相同的逻辑:
- 在登录步骤前添加会话检查步骤
- 给登录相关的编排步骤添加
Precondition,当objectId存在时跳过登录,直接进入密码重置页面
三、验证要点
- 已登录用户访问编辑资料/重置密码流程,应直接进入对应操作页面,无需重复输入账号密码
- 未登录用户访问时,仍需正常触发登录验证流程,再进入操作环节
内容的提问来源于stack exchange,提问作者uppercase
相关产品推荐
相关产品推荐

