AD B2C中CompareClaims触发内部服务器错误排查求助
AD B2C声明比对内部错误排查与修复
核心问题分析
你的配置触发内部服务器错误,根源在于以下几点:
- 错误选用
SelfAssertedAttributeProvider作为声明转换的TechnicalProfile处理器,该组件用于收集用户输入,不适合无交互的声明比对操作 - Precondition逻辑反转,导致错误分支执行异常
- 布尔值大小写不匹配,AD B2C中布尔类型值为小写
true/false,你使用了大写True
修复步骤
1. 替换声明转换的TechnicalProfile处理器
将CheckAgencyMatch的处理器改为ClaimsTransformationProvider,这是专门用于无交互执行声明转换的组件:
<TechnicalProfile Id="CheckAgencyMatch"> <DisplayName>Check Agency Match</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <IncludeInSso>false</IncludeInSso> <InputClaims> <InputClaim ClaimTypeReferenceId="agency" Required="true" /> <InputClaim ClaimTypeReferenceId="extension_agency" Required="true" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="agency"/> <OutputClaim ClaimTypeReferenceId="extension_agency" /> <OutputClaim ClaimTypeReferenceId="agencyClaimMatch"/> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="checkSameAgency"/> </OutputClaimsTransformations> </TechnicalProfile>
2. 修正Precondition逻辑与布尔值格式
调整第7步的Precondition逻辑,将ExecuteActionsIf改为true,并把匹配值改为小写true,确保声明不匹配时执行错误提示步骤:
<!-- Check if agencyID Match--> <OrchestrationStep Order="7" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>agencyClaimMatch</Value> <Value>true</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="SelfAssertedAgencyNotMatched" TechnicalProfileReferenceId="SelfAssertedAgencyNotMatched" /> </ClaimsExchanges> </OrchestrationStep>
3. 确保错误提示TechnicalProfile配置正确
确认SelfAssertedAgencyNotMatched已正确配置,用于展示错误信息并引导跳转登录,示例配置如下:
<TechnicalProfile Id="SelfAssertedAgencyNotMatched"> <DisplayName>Agency Mismatch Error</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted.error</Item> <Item Key="showContinueButton">false</Item> <Item Key="showCancelButton">true</Item> <Item Key="cancelButtonTarget">https://your-login-url.com</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="errorMessage" DefaultValue="Agency information does not match. Please log in again." /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="errorMessage" /> </OutputClaims> </TechnicalProfile>
验证修复
完成修改后重新上传AD B2C自定义策略,测试两种场景:
- 当
agency与extension_agency匹配时,流程正常推进并颁发JWT令牌 - 当二者不匹配时,显示错误页面并跳转至登录页
内容的提问来源于stack exchange,提问作者user14013917
相关产品推荐
相关产品推荐

