Azure AAD B2C自定义策略添加extension_UserRole后未在JWT中显示的问题咨询
Azure AAD B2C自定义属性extension_UserRole显示问题修改建议
针对你遇到的自定义属性extension_UserRole未在登录环节及JWT令牌中显示的问题,可按以下步骤修改自定义策略:
在ClaimsSchema中定义属性
打开自定义策略的基础文件,在<ClaimsSchema>节点下添加该属性的定义,确保策略能识别这个属性:<ClaimType Id="extension_UserRole"> <DisplayName>User Role</DisplayName> <DataType>string</DataType> <UserHelpText>用户在系统中的角色</UserHelpText> </ClaimType>在用户信息读取步骤中添加属性输出
找到登录流程中读取用户信息的TechnicalProfile(通常是AAD-UserReadUsingEmailAddress或AAD-UserReadUsingObjectId),在其<OutputClaims>节点中加入该属性,让策略从AAD中读取这个值:<OutputClaim ClaimTypeReferenceId="extension_UserRole" />在令牌签发环节包含该属性
定位到负责签发JWT的TechnicalProfile(一般为JwtIssuer),在它的<OutputClaims>里添加该属性,确保属性被写入最终的JWT令牌:<OutputClaim ClaimTypeReferenceId="extension_UserRole" />注册流程同步配置(如需用户注册时设置)
如果需要用户在注册时填写该角色,在注册对应的TechnicalProfile(如LocalAccountSignUpWithLogonEmail)中,同时配置<OutputClaims>(展示输入框)和<PersistedClaims>(持久化到AAD):<OutputClaim ClaimTypeReferenceId="extension_UserRole" Required="false" /> <PersistedClaim ClaimTypeReferenceId="extension_UserRole" />验证基础配置
- 确认Azure门户中已成功创建
extension_UserRole属性 - 检查自定义策略中使用的应用程序ID拥有读取该属性的权限
- 确认Azure门户中已成功创建
测试前清理缓存
修改策略后,使用浏览器无痕模式或清理缓存后测试,避免旧策略缓存干扰结果
内容的提问来源于stack exchange,提问作者Nikhil Mittal
相关产品推荐
相关产品推荐

