You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略中多查询字符串参数处理方案咨询

在Azure AD B2C自定义策略中传递查询参数至JWT令牌

实现步骤

1. 定义自定义声明

在TrustFrameworkExtensions.xml的<ClaimsSchema>节点下,添加对应查询参数的声明,用于存储传递过来的值:

<ClaimType Id="userName">
  <DisplayName>User Name</DisplayName>
  <DataType>string</DataType>
  <UserHelpText>用户从Web应用传入的名称</UserHelpText>
</ClaimType>
<ClaimType Id="webApp">
  <DisplayName>Web App ID</DisplayName>
  <DataType>string</DataType>
  <UserHelpText>Web应用传入的标识ID</UserHelpText>
</ClaimType>

2. 捕获请求中的查询参数

在处理登录/注册的技术配置(比如SelfAsserted-LocalAccountSignin-Email)中,添加<InputClaims>节点,用B2C内置的{OAUTH-KV:参数名}表达式提取URL中的查询参数,映射到自定义声明:

<TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="userName" PartnerClaimType="userName" DefaultValue="{OAUTH-KV:userName}" />
    <InputClaim ClaimTypeReferenceId="webApp" PartnerClaimType="webApp" DefaultValue="{OAUTH-KV:webApp}" />
  </InputClaims>
</TechnicalProfile>

3. 将声明注入JWT令牌

在负责颁发令牌的JwtIssuer技术配置中,把自定义声明添加到<OutputClaims>节点,确保令牌包含这些参数:

<TechnicalProfile Id="JwtIssuer">
  <OutputClaims>
    <!-- 保留原有输出声明,如sub、name等 -->
    <OutputClaim ClaimTypeReferenceId="userName" />
    <OutputClaim ClaimTypeReferenceId="webApp" />
  </OutputClaims>
</TechnicalProfile>

4. 更新用户流的依赖方配置

在你的登录/注册用户流策略(比如SignUpOrSignin.xml)的<RelyingParty>节点下,把自定义声明加入<OutputClaims>,确保策略最终输出这些值:

<RelyingParty>
  <DefaultUserJourney ReferenceId="SignUpOrSignIn" />
  <TechnicalProfile Id="PolicyProfile">
    <DisplayName>PolicyProfile</DisplayName>
    <Protocol Name="OpenIdConnect" />
    <OutputClaims>
      <!-- 保留原有输出声明 -->
      <OutputClaim ClaimTypeReferenceId="userName" />
      <OutputClaim ClaimTypeReferenceId="webApp" />
    </OutputClaims>
    <SubjectNamingInfo ClaimType="sub" />
  </TechnicalProfile>
</RelyingParty>

测试验证

构造包含查询参数的认证请求URL,完成登录/注册流程后,解析返回的JWT令牌,检查userName和webApp声明是否存在且值与传入的一致:

https://yourtenant.b2clogin.com/yourtenant.onmicrosoft.com/B2C_1A_signup_signin/oauth2/v2.0/authorize?client_id=你的客户端ID&redirect_uri=https://你的应用回调地址&response_type=id_token&scope=openid&nonce=随机值&userName=John&webApp=37658

内容的提问来源于stack exchange,提问作者CloudSpace03

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 20:20:36