Azure B2C 社交注册/登录的服务条款复选框实现及报错排查
问题原因排查
你遇到的500内部服务错误,基本是以下几个配置缺失导致的:
- 未在声明架构中预先定义
extension_termsOfUseConsentChoice、currentTime等自定义声明,B2C无法识别未定义的声明直接调用就会触发服务错误 - 写入用户属性时使用的
currentTime声明未赋值,空值写入扩展属性触发写入失败 - 自定义扩展属性没有配置正确的目录属性映射,导致AAD写入用户属性时找不到对应字段
修复步骤
1. 先在策略的节点下添加声明定义
<ClaimsSchema> <!-- 服务条款同意选择声明 --> <ClaimType Id="extension_termsOfUseConsentChoice"> <DisplayName>同意服务条款</DisplayName> <DataType>string</DataType> <UserInputType>CheckboxMultiSelect</UserInputType> <Restriction> <Enumeration Text="我已阅读并同意服务条款" Value="AgreeToTermsOfUseConsentYes" SelectByDefault="false" /> </Restriction> <!-- 这里替换为你B2C租户内b2c-extensions-app的应用ID,去掉所有横杠 --> <PartnerClaimType>extension_1234567890abcdef1234567890abcdef_termsOfUseConsentChoice</PartnerClaimType> </ClaimType> <!-- 同意时间声明 --> <ClaimType Id="extension_termsOfUseConsentDateTime"> <DisplayName>服务条款同意时间</DisplayName> <DataType>dateTime</DataType> <PartnerClaimType>extension_1234567890abcdef1234567890abcdef_termsOfUseConsentDateTime</PartnerClaimType> </ClaimType> <!-- 同意版本声明 --> <ClaimType Id="extension_termsOfUseConsentVersion"> <DisplayName>服务条款版本</DisplayName> <DataType>string</DataType> <PartnerClaimType>extension_1234567890abcdef1234567890abcdef_termsOfUseConsentVersion</PartnerClaimType> </ClaimType> </ClaimsSchema>
注意:你需要先在B2C租户的「应用注册」中找到所有应用里的b2c-extensions-app,复制它的应用ID,去掉所有横杠后替换上面代码里的前缀部分
2. 修正AAD-UserWriteUsingAlternativeSecurityId技术配置文件
补充currentTime的赋值逻辑,避免空值写入:
<TechnicalProfile Id="AAD-UserWriteUsingAlternativeSecurityId"> <InputClaims> <!-- 直接从B2C上下文获取当前UTC时间赋值给currentTime --> <InputClaim ClaimTypeReferenceId="currentTime" DefaultValue="{Context:DateTimeInUtc}" /> </InputClaims> <PersistedClaims> <PersistedClaim ClaimTypeReferenceId="displayName" DefaultValue="unknown" /> <PersistedClaim ClaimTypeReferenceId="email" PartnerClaimType="signInNames.emailAddress" /> <PersistedClaim ClaimTypeReferenceId="currentTime" PartnerClaimType="extension_termsOfUseConsentDateTime" /> <PersistedClaim ClaimTypeReferenceId="extension_termsOfUseConsentChoice" /> <PersistedClaim ClaimTypeReferenceId="extension_termsOfUseConsentVersion" DefaultValue="V1" /> </PersistedClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="displayName" /> <OutputClaim ClaimTypeReferenceId="surname" /> <OutputClaim ClaimTypeReferenceId="signInNames.emailAddress" /> <OutputClaim ClaimTypeReferenceId="objectId" /> </OutputClaims> </TechnicalProfile>
3. 验证用户旅程顺序
确保你在用户旅程中,社交IDP回调的编排步骤之后、令牌生成步骤之前,添加了调用SelfAsserted-Social技术配置文件的编排步骤,且触发条件为新用户注册场景:
<OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <!-- 仅新注册的社交账号触发服务条款确认 --> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>newUser</Value> <Value>True</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>identityProvider</Value> <Value>localAccount</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="SocialTermsOfUseExchange" TechnicalProfileReferenceId="SelfAsserted-Social" /> </ClaimsExchanges> </OrchestrationStep>
额外排查建议
如果修改后仍然报错,可以开启B2C策略的日志记录功能,查看具体的错误栈信息,确认是声明缺失还是属性写入权限问题。
内容的提问来源于stack exchange,提问作者ATrivino
相关产品推荐
相关产品推荐

