登录时密码值无法通过REST API从Azure AD B2C传递到Azure Function
解决Azure AD B2C登录时传递密码至Azure Function的问题
核心限制说明
Azure AD B2C默认会屏蔽密码这类敏感字段,不会将其包含在用户旅程的输出声明或API调用参数中,这是安全设计层面的限制。要实现密码传递,必须通过自定义策略的特定配置来突破这个限制。
具体实现步骤
1. 定义密码输入声明
在TrustFrameworkExtensions.xml的<ClaimsSchema>节点下添加密码声明,明确字段类型:
<ClaimType Id="password"> <DisplayName>Password</DisplayName> <DataType>string</DataType> <UserHelpText>Enter your password</UserHelpText> <UserInputType>Password</UserInputType> </ClaimType>
2. 在登录技术配置中保留密码声明
找到登录对应的<TechnicalProfile>(比如默认的SelfAsserted-LocalAccountSignin-Email),在<OutputClaims>里添加密码声明,确保登录时收集并保留该字段:
<TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email"> <InputClaims> <InputClaim ClaimTypeReferenceId="signInName" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="email" /> <OutputClaim ClaimTypeReferenceId="password" /> <!-- 保留密码声明 --> </OutputClaims> </TechnicalProfile>
3. 配置Azure Function调用的参数传递
在调用Azure Function的<TechnicalProfile>中,将密码声明作为输入参数传入:
<TechnicalProfile Id="REST-AzureFunction"> <DisplayName>Azure Function Call</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://your-function-url.azurewebsites.net/api/your-function</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="email" /> <InputClaim ClaimTypeReferenceId="password" PartnerClaimType="password" /> <!-- 传递密码参数 --> </InputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile>
4. 在用户旅程中加入API调用步骤
在用户旅程的<OrchestrationStep>里,添加调用Azure Function的步骤,注意要放在登录信息收集完成之后:
<OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="CallAzureFunction" TechnicalProfileReferenceId="REST-AzureFunction" /> </ClaimsExchanges> </OrchestrationStep>
重要安全提醒
- 必须确保Azure Function的通信全程使用HTTPS加密,禁止明文传输密码。
- 处理完密码后要立即清除内存中的相关数据,绝对不能持久化存储密码。
- 仅在业务刚需场景下使用此方案,尽量遵循Azure AD B2C的安全设计原则,避免敏感数据不必要的暴露。
内容的提问来源于stack exchange,提问作者SoeHtet Zaw
相关产品推荐
相关产品推荐

