You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略中如何获取登录请求的aud与scope声明?

解决Azure AD B2C自定义策略中传递Audience和Scope到REST API的问题

问题原因

你之前的配置无法获取aud和scope,核心原因是:

  • Azure AD B2C中没有默认的aud声明,登录请求里的受众(即前端应用的客户端ID)对应的是client_id声明
  • 请求中的scope不会自动存入声明集合,需要通过声明解析器显式捕获

解决方案步骤

1. 添加声明类型定义

在自定义策略的<ClaimsSchema>节点下,新增client_id和requested_scope的声明类型:

<ClaimsSchema>
  <!-- 保留现有声明定义 -->
  <ClaimType Id="client_id">
    <DisplayName>客户端ID</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
  <ClaimType Id="requested_scope">
    <DisplayName>请求的Scope</DisplayName>
    <DataType>string</DataType>
  </ClaimType>
</ClaimsSchema>

2. 捕获请求中的Client ID和Scope

创建专门的技术配置,用于从登录请求中提取这两个参数:

<TechnicalProfile Id="GetRequestParameters">
  <DisplayName>获取请求参数</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="IncludeClaimResolvingInClaimsHandling">true</Item>
  </Metadata>
  <OutputClaims>
    <!-- 从OAuth2请求中提取客户端ID -->
    <OutputClaim ClaimTypeReferenceId="client_id" DefaultValue="{OAuth2:ClientId}" />
    <!-- 从OAuth2请求中提取Scope参数 -->
    <OutputClaim ClaimTypeReferenceId="requested_scope" DefaultValue="{OAuth2:Scope}" />
  </OutputClaims>
</TechnicalProfile>

3. 在用户旅程中插入参数捕获步骤

在调用你的REST-API技术配置之前,先执行上面的GetRequestParameters配置,确保参数被存入声明集合:

<UserJourney Id="SignIn">
  <!-- 保留现有步骤 -->
  <OrchestrationStep Order="X" Type="ClaimsExchange">
    <ClaimsExchanges>
      <ClaimsExchange Id="FetchRequestParams" TechnicalProfileReferenceId="GetRequestParameters" />
    </ClaimsExchanges>
  </OrchestrationStep>
  <!-- 后续调用REST-API的步骤 -->
</UserJourney>

4. 修改REST-API技术配置的输入声明

更新你的REST-API配置,使用正确的声明传递aud和scope:

<TechnicalProfile Id="REST-API">
  <!-- 保留现有配置 -->
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="email" />
    <InputClaim ClaimTypeReferenceId="givenName" />
    <InputClaim ClaimTypeReferenceId="surname" />
    <!-- 将client_id映射为aud传递给API -->
    <InputClaim ClaimTypeReferenceId="client_id" PartnerClaimType="aud" />
    <!-- 将捕获的scope传递给API -->
    <InputClaim ClaimTypeReferenceId="requested_scope" PartnerClaimType="scope" />
    <InputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
  </InputClaims>
  <!-- 保留现有输出声明 -->
</TechnicalProfile>

额外说明

  • 如果前端应用请求时指定了多个scope,{OAuth2:Scope}会返回用空格分隔的完整字符串
  • client_id就是前端应用在Azure AD B2C中注册的客户端ID,可直接用于区分不同应用的请求

内容的提问来源于stack exchange,提问作者RichJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 16:25:39