You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C仅注册流程会话管理:需保留会话但不跳过注册界面

自定义策略中注册流程的会话控制实现方案

核心思路

登录流程依赖SM-AAD的会话检查逻辑来跳过已登录状态下的页面,但注册流程需要禁用会话检查,同时保留注册完成后创建新会话的能力。我们可以通过自定义会话管理技术配置文件,剥离会话读取/检查逻辑,只保留会话写入功能来实现需求。

具体操作步骤

1. 自定义会话管理技术配置文件

在策略的<ClaimsProviders>节点下,新增一个会话管理配置,命名为SM-AAD-NoSessionCheck。该配置复制SM-AAD的会话写入逻辑,但移除所有会话检查相关的设置:

<ClaimsProvider>
  <DisplayName>Session Management</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="SM-AAD-NoSessionCheck">
      <DisplayName>No-Check Session Management</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.SSO.DefaultSSOSessionProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <Metadata>
        <Item Key="SessionStorageType">SessionCookie</Item>
        <Item Key="ReuseSSOSessionFromOtherProviders">false</Item>
      </Metadata>
      <PersistedClaims>
        <PersistedClaim ClaimTypeReferenceId="objectId" />
        <PersistedClaim ClaimTypeReferenceId="email" />
      </PersistedClaims>
      <!-- 不设置OutputClaims,跳过会话声明读取逻辑 -->
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

2. 修改注册技术配置文件的会话引用

找到注册流程对应的技术配置文件(比如LocalAccountSignUpWithLogonEmail),将原有的SM-AAD会话引用替换为自定义的SM-AAD-NoSessionCheck:

<TechnicalProfile Id="LocalAccountSignUpWithLogonEmail">
  <!-- 其他原有配置保持不变 -->
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD-NoSessionCheck" />
</TechnicalProfile>

3. 可选:强制清除已有会话(彻底重置注册流程)

如果需要确保注册流程完全不受已有会话影响,可以在注册用户旅程的第一步添加清除会话的步骤:

<OrchestrationStep Order="1" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="ClearExistingSession" TechnicalProfileReferenceId="SM-ClearSession" />
  </ClaimsExchanges>
</OrchestrationStep>

对应的清除会话技术配置文件:

<TechnicalProfile Id="SM-ClearSession">
  <DisplayName>Clear Session Provider</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.SSO.DefaultSSOSessionProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="SessionStorageType">SessionCookie</Item>
    <Item Key="DeleteSession">true</Item>
  </Metadata>
</TechnicalProfile>

效果说明

  • 注册流程不再检查已有会话,无论用户是否登录,都会直接进入注册界面从头开始流程;
  • 注册完成后,自定义的会话配置依然会创建新的用户会话,满足保留会话的需求。

内容的提问来源于stack exchange,提问作者fei0x

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 21:50:39