You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

实现邮箱输入与登录注册步骤分离的AD B2C自定义策略

AD B2C 邮箱分步校验自定义策略实现方案

这个需求属于本地账户场景下的分步登录/注册分支流程,核心逻辑是先收集邮箱做存在性校验,再根据结果跳转对应页面,具体开发可以从以下环节入手:


1. 调整初始步骤为仅邮箱收集页

首先替换默认SignUpOrSignIn用户旅程的第一步,新增仅收集邮箱的自断言页面:

  • 定义新的自断言技术配置文件SelfAsserted-EmailCollection,仅保留邮箱字段作为必填声明,输出的邮箱值存入signInName声明
  • 将该技术配置文件设为用户旅程的第一个编排步骤

示例配置:

<TechnicalProfile Id="SelfAsserted-EmailCollection">
  <DisplayName>输入邮箱</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null"/>
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
  </Metadata>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="signInName" DisplayName="邮箱" Required="true" RegularExpression="^[a-zA-Z0-9.!#$%&amp;'^_`{}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*$" />
  </OutputClaims>
</TechnicalProfile>

2. 新增邮箱存在性校验步骤

在收集到邮箱后,调用目录读取能力校验用户是否存在:

  • 复用AAD-UserReadUsingSignInName技术配置文件,入参为第一步收集的signInName
  • 新增错误处理逻辑:当返回用户不存在错误时,不直接抛出异常,而是将objectId声明设为固定值NOT_FOUND,用于后续分支判断

示例错误处理配置:

<TechnicalProfile Id="AAD-UserReadUsingSignInName">
  <!-- 保留原有基础配置 -->
  <ErrorHandlers>
    <ErrorHandler>
      <ErrorCondition>UserNotFound</ErrorCondition>
      <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="objectId" DefaultValue="NOT_FOUND" AlwaysUseDefaultValue="true"/>
      </OutputClaims>
    </ErrorHandler>
  </ErrorHandlers>
</TechnicalProfile>

3. 配置分支跳转逻辑

根据objectId的值判断后续跳转路径,两个分支都要预填充第一步收集的邮箱,避免用户重复输入:

  • 若objectId存在且不为NOT_FOUND:跳转至密码收集页面,邮箱字段设为只读
  • 若objectId等于NOT_FOUND:跳转至注册页面,邮箱字段设为只读

用户旅程编排步骤示例:

<OrchestrationStep Order="1" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="EmailCollection" TechnicalProfileReferenceId="SelfAsserted-EmailCollection"/>
  </ClaimsExchanges>
</OrchestrationStep>
<OrchestrationStep Order="2" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
      <Value>objectId</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="CheckUserExists" TechnicalProfileReferenceId="AAD-UserReadUsingSignInName"/>
  </ClaimsExchanges>
</OrchestrationStep>
<!-- 未注册用户走注册分支 -->
<OrchestrationStep Order="3" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
      <Value>objectId</Value>
      <Value>NOT_FOUND</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="SignupFlow" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignup-Email"/>
  </ClaimsExchanges>
</OrchestrationStep>
<!-- 已注册用户走密码登录分支 -->
<OrchestrationStep Order="4" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
      <Value>objectId</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>objectId</Value>
      <Value>NOT_FOUND</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="PasswordCollection" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Password"/>
  </ClaimsExchanges>
</OrchestrationStep>
<!-- 后续保留原有令牌发放等步骤即可 -->

内容的提问来源于stack exchange,提问作者Vanya Makhlinets

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 10:36:03