将SAML布尔属性映射到AAD B2C布尔声明时类型不匹配问题咨询
SAML布尔属性在AAD B2C自定义策略中的处理方案
你尝试将SAML 2.0身份提供商返回的布尔属性直接映射到AAD B2C自定义策略的boolean类型声明时遇到了类型不匹配错误,具体情况如下:
SAML返回的属性示例
<saml:Attribute Name="http://schemas.custom/claim/booleanexample" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml:AttributeValue>True</saml:AttributeValue> </saml:Attribute>
错误信息
The data type 'String' of claim with id 'http://schemas.custom/claim/booleanexample' does not match the Data Type 'Boolean' of claimType with id 'BooleanExample' specified in the policy.
自定义策略中的布尔声明定义
<ClaimType Id="BooleanExample"> <DataType>boolean</DataType> </ClaimType>
你尝试过传递0/1、True/False、true/false等值,但均无法直接映射到布尔声明,且SAML的AttributeValue本身是xs:any类型,无法显式指定数据类型。
没错,你必须先通过字符串类型的声明接收SAML返回的属性值,再通过**声明转换(Claims Transformation)**将其转换为布尔类型声明,具体步骤如下:
- 定义临时字符串声明
在ClaimsSchema中添加一个字符串类型的声明,用于接收SAML返回的原始属性值:
<ClaimType Id="BooleanExampleString"> <DataType>string</DataType> </ClaimType>
- 配置SAML属性到字符串声明的映射
在SAML身份提供商的OutputClaims配置中,将SAML属性映射到这个临时字符串声明:
<OutputClaim ClaimTypeReferenceId="BooleanExampleString" PartnerClaimType="http://schemas.custom/claim/booleanexample" />
- 添加字符串转布尔的声明转换
在ClaimsTransformations节点下添加转换规则,支持识别True/true/1为true,False/false/0为false:
<ClaimsTransformation Id="ConvertStringToBoolean" TransformationMethod="ConvertStringToBoolean"> <InputClaims> <InputClaim ClaimTypeReferenceId="BooleanExampleString" TransformationClaimType="inputClaim" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="BooleanExample" TransformationClaimType="outputClaim" /> </OutputClaims> </ClaimsTransformation>
- 在用户旅程中调用声明转换
在对应的TechnicalProfile(比如SAML身份提供商的技术配置或后续的编排步骤)中,添加对这个转换的调用:
<TechnicalProfile Id="YourSAMLIdP"> <!-- 其他配置 --> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="ConvertStringToBoolean" /> </OutputClaimsTransformations> </TechnicalProfile>
这样处理后,AAD B2C就能正确识别布尔值,并基于BooleanExample声明执行后续逻辑了。
内容的提问来源于stack exchange,提问作者53280-1
相关产品推荐
相关产品推荐

