You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

登录时密码值无法通过REST API从Azure AD B2C传递到Azure Function

解决Azure AD B2C登录时传递密码至Azure Function的问题

核心限制说明

Azure AD B2C默认会屏蔽密码这类敏感字段,不会将其包含在用户旅程的输出声明或API调用参数中,这是安全设计层面的限制。要实现密码传递,必须通过自定义策略的特定配置来突破这个限制。

具体实现步骤

1. 定义密码输入声明

在TrustFrameworkExtensions.xml的<ClaimsSchema>节点下添加密码声明,明确字段类型:

<ClaimType Id="password">
  <DisplayName>Password</DisplayName>
  <DataType>string</DataType>
  <UserHelpText>Enter your password</UserHelpText>
  <UserInputType>Password</UserInputType>
</ClaimType>

2. 在登录技术配置中保留密码声明

找到登录对应的<TechnicalProfile>(比如默认的SelfAsserted-LocalAccountSignin-Email),在<OutputClaims>里添加密码声明,确保登录时收集并保留该字段:

<TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInName" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="email" />
    <OutputClaim ClaimTypeReferenceId="password" /> <!-- 保留密码声明 -->
  </OutputClaims>
</TechnicalProfile>

3. 配置Azure Function调用的参数传递

在调用Azure Function的<TechnicalProfile>中,将密码声明作为输入参数传入:

<TechnicalProfile Id="REST-AzureFunction">
  <DisplayName>Azure Function Call</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://your-function-url.azurewebsites.net/api/your-function</Item>
    <Item Key="AuthenticationType">None</Item>
    <Item Key="SendClaimsIn">Body</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="email" />
    <InputClaim ClaimTypeReferenceId="password" PartnerClaimType="password" /> <!-- 传递密码参数 -->
  </InputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

4. 在用户旅程中加入API调用步骤

在用户旅程的<OrchestrationStep>里,添加调用Azure Function的步骤,注意要放在登录信息收集完成之后:

<OrchestrationStep Order="2" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="CallAzureFunction" TechnicalProfileReferenceId="REST-AzureFunction" />
  </ClaimsExchanges>
</OrchestrationStep>

重要安全提醒

  • 必须确保Azure Function的通信全程使用HTTPS加密,禁止明文传输密码。
  • 处理完密码后要立即清除内存中的相关数据,绝对不能持久化存储密码。
  • 仅在业务刚需场景下使用此方案,尽量遵循Azure AD B2C的安全设计原则,避免敏感数据不必要的暴露。

内容的提问来源于stack exchange,提问作者SoeHtet Zaw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 00:50:29