You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略无法获取Apple撤销令牌端点的有效idp_access_token

问题:Azure AD B2C中获取有效的Apple访问令牌以满足应用商店账户删除要求

背景

Apple应用商店要求应用必须具备删除用户账户及撤销令牌的能力。当前在Azure AD B2C中配置Apple登录后,获取到的idp_access_token是类似af42702403427436e915f761ddd1e0ed4.0.srrst.aOw1NWI0uV78qwwNrzV7VA的字符串,无法用于Apple的令牌撤销端点。

若仅删除B2C用户但不撤销Apple令牌,用户下次用同一Apple账户创建B2C账户时,Apple不会再传递邮箱和姓名信息——因为Apple仅在首次授权时发送这类数据。

当前配置(TrustFrameworkExtensions.xml中的Apple声明提供程序)

<ClaimsProvider>
<Domain>apple.com</Domain> <DisplayName>Sign in with Apple</DisplayName> <TechnicalProfiles>
<TechnicalProfile Id="Apple-OIDC">
<DisplayName>Sign in with Apple</DisplayName> 
<Protocol Name="OpenIdConnect"/> 
<Metadata>
<Item Key="ProviderName">apple</Item>
<Item Key="authorization_endpoint">https://appleid.apple.com/auth/authorize</Item> 
<Item Key="AccessTokenEndpoint">https://appleid.apple.com/auth/token</Item>
<Item Key="JWKS">https://appleid.apple.com/auth/keys</Item>
<Item Key="issuer">https://appleid.apple.com</Item>
<Item Key="scope">name email openid</Item>
<Item Key="HttpBinding">POST</Item>
<Item Key="response_types">code</Item>
<Item Key="external_user_identity_claim_id">sub</Item>
<Item Key="response_mode">form_post</Item>
<Item Key="client_id">xxxxx</Item>
<Item Key="IdTokenAudience">xxxxx</Item>
<Item Key="UsePolicyInRedirectUri">0</Item>
<Item Key="ReadBodyClaimsOnIdpRedirect">user.email user.name.firstName user.name.lastName</Item>
</Metadata>
<CryptographicKeys><Key Id="client_secret" StorageReferenceId="xxxxx" /> </CryptographicKeys>
<InputClaims />
<OutputClaims>
<OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" Required = "true"/>
<OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="user.email" Required = "true"/>
<OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="user.name.firstName" DefaultValue="" />
<OutputClaim ClaimTypeReferenceId="surName" PartnerClaimType="user.name.lastName" DefaultValue="" />
<OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="https://appleid.apple.com/" AlwaysUseDefaultValue="true" /> 
<OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication" AlwaysUseDefaultValue="true" />
<OutputClaim ClaimTypeReferenceId="identityProviderAccessToken" PartnerClaimType="{oauth2:access_token}" />
</OutputClaims> 
<OutputClaimsTransformations>
<OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" /> 
<OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" /> 
<OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> 
<OutputClaimsTransformation ReferenceId="CreateSubjectClaimFromAlternativeSecurityId" />
</OutputClaimsTransformations>
<UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" />
</TechnicalProfile> 
</TechnicalProfiles> 
</ClaimsProvider>

尝试过的方案及问题

尝试修改技术配置文件的MetaData元素,添加v2.0 OpenID配置URL后,B2C与Apple认证过程中出现access_denied错误。

请求

需要解决方案以获取可正常用于Apple令牌撤销端点的有效访问令牌。

内容的提问来源于stack exchange,提问作者Notion

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 22:10:27