移除Azure AD B2C社交注册输入表单,实现无缝注册流程
社交账号首次注册无缝流程解决方案
核心思路
复用Google等身份提供商返回的DisplayName、Given Name、Last Name属性,跳过SelfAsserted-Social-v2页面的用户输入环节,同时保留该技术配置文件生成随机密码的逻辑,实现无缝注册/登录。
具体修改步骤
1. 确认身份提供商属性返回
确保Google等IDP的配置中已请求并返回目标属性,以Google为例,在其ClaimsProvider的OutputClaims中添加:
<OutputClaim ClaimTypeReferenceId="displayName" /> <OutputClaim ClaimTypeReferenceId="givenName" /> <OutputClaim ClaimTypeReferenceId="surname" />
2. 改造SelfAsserted-Social-v2技术配置文件
找到SelfAsserted-Social-v2配置,调整为以下内容:
<TechnicalProfile Id="SelfAsserted-Social-v2"> <DisplayName>User ID signup</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted.social</Item> <!-- 隐藏继续按钮,开启自动提交 --> <Item Key="setting.showContinueButton">false</Item> <Item Key="setting.automaticRetryOnError">true</Item> </Metadata> <InputClaims> <!-- 用IDP返回的属性预填充字段 --> <InputClaim ClaimTypeReferenceId="displayName" DefaultValue="{OIDC:DisplayName}" /> <InputClaim ClaimTypeReferenceId="givenName" DefaultValue="{OIDC:GivenName}" /> <InputClaim ClaimTypeReferenceId="surname" DefaultValue="{OIDC:Surname}" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="displayName" Required="true" /> <OutputClaim ClaimTypeReferenceId="givenName" Required="true" /> <OutputClaim ClaimTypeReferenceId="surname" Required="true" /> <!-- 保留随机密码生成逻辑 --> <OutputClaim ClaimTypeReferenceId="newPassword" Required="true" /> </OutputClaims> <ValidationTechnicalProfiles> <ValidationTechnicalProfile ReferenceId="AAD-UserWriteUsingAlternativeSecurityId" /> </ValidationTechnicalProfiles> </TechnicalProfile>
3. 设置属性为隐藏输入
在ClaimType定义中,将目标属性的UserInputType设为Hidden,避免显示输入框:
<ClaimType Id="displayName"> <DisplayName>Display Name</DisplayName> <DataType>string</DataType> <UserInputType>Hidden</UserInputType> </ClaimType> <ClaimType Id="givenName"> <DisplayName>Given Name</DisplayName> <DataType>string</DataType> <UserInputType>Hidden</UserInputType> </ClaimType> <ClaimType Id="surname"> <DisplayName>Surname</DisplayName> <DataType>string</DataType> <UserInputType>Hidden</UserInputType> </ClaimType>
4. 验证编排步骤顺序
确保用户旅程中先执行IDP认证步骤,再执行SelfAsserted-Social-v2,保证属性已被正确获取。
注意事项
- 若部分IDP未返回某属性(如部分平台无
surname),可设置DefaultValue=""避免流程报错 - 确认
AAD-UserWriteUsingAlternativeSecurityId已正确将属性写入B2C用户存储
内容的提问来源于stack exchange,提问作者user14103982
相关产品推荐
相关产品推荐

