You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AD B2C中CompareClaims触发内部服务器错误排查求助

AD B2C声明比对内部错误排查与修复

核心问题分析

你的配置触发内部服务器错误,根源在于以下几点:

  • 错误选用SelfAssertedAttributeProvider作为声明转换的TechnicalProfile处理器,该组件用于收集用户输入,不适合无交互的声明比对操作
  • Precondition逻辑反转,导致错误分支执行异常
  • 布尔值大小写不匹配,AD B2C中布尔类型值为小写true/false,你使用了大写True

修复步骤

1. 替换声明转换的TechnicalProfile处理器

将CheckAgencyMatch的处理器改为ClaimsTransformationProvider,这是专门用于无交互执行声明转换的组件:

<TechnicalProfile Id="CheckAgencyMatch">
    <DisplayName>Check Agency Match</DisplayName>
    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
    <IncludeInSso>false</IncludeInSso>
    <InputClaims>
        <InputClaim ClaimTypeReferenceId="agency" Required="true" />
        <InputClaim ClaimTypeReferenceId="extension_agency" Required="true" />
    </InputClaims>
    <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="agency"/>
        <OutputClaim ClaimTypeReferenceId="extension_agency" />
        <OutputClaim ClaimTypeReferenceId="agencyClaimMatch"/>
    </OutputClaims>
    <OutputClaimsTransformations>
        <OutputClaimsTransformation ReferenceId="checkSameAgency"/>
    </OutputClaimsTransformations>
</TechnicalProfile>

2. 修正Precondition逻辑与布尔值格式

调整第7步的Precondition逻辑,将ExecuteActionsIf改为true,并把匹配值改为小写true,确保声明不匹配时执行错误提示步骤:

<!-- Check if agencyID Match-->
<OrchestrationStep Order="7" Type="ClaimsExchange">
    <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
            <Value>agencyClaimMatch</Value>
            <Value>true</Value>
            <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
    </Preconditions>
    <ClaimsExchanges>
        <ClaimsExchange Id="SelfAssertedAgencyNotMatched" TechnicalProfileReferenceId="SelfAssertedAgencyNotMatched" />
    </ClaimsExchanges>
</OrchestrationStep>

3. 确保错误提示TechnicalProfile配置正确

确认SelfAssertedAgencyNotMatched已正确配置,用于展示错误信息并引导跳转登录,示例配置如下:

<TechnicalProfile Id="SelfAssertedAgencyNotMatched">
    <DisplayName>Agency Mismatch Error</DisplayName>
    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
    <Metadata>
        <Item Key="ContentDefinitionReferenceId">api.selfasserted.error</Item>
        <Item Key="showContinueButton">false</Item>
        <Item Key="showCancelButton">true</Item>
        <Item Key="cancelButtonTarget">https://your-login-url.com</Item>
    </Metadata>
    <InputClaims>
        <InputClaim ClaimTypeReferenceId="errorMessage" DefaultValue="Agency information does not match. Please log in again." />
    </InputClaims>
    <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="errorMessage" />
    </OutputClaims>
</TechnicalProfile>

验证修复

完成修改后重新上传AD B2C自定义策略,测试两种场景:

  • 当agency与extension_agency匹配时,流程正常推进并颁发JWT令牌
  • 当二者不匹配时,显示错误页面并跳转至登录页

内容的提问来源于stack exchange,提问作者user14013917

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 22:32:21