如何在msal-angular中强制用户使用双因素身份认证
问题说明
我尝试使用msal-angular实现双因素登录,希望强制用户使用双因素认证,优先使用Authenticator应用。
目前我仅完成了仅要求用户输入密码的配置,我的配置如下:
const isIE = window.navigator.userAgent.indexOf('MSIE ') > -1 || window.navigator.userAgent.indexOf('Trident/') > -1; export const protectedResourceMap: [string, string[]][] = [ ['https://graph.microsoft.com/v1.0/me', ['user.read']] ]; @NgModule({ imports: [ CommonModule, MsalModule.forRoot({ auth: { clientId: '*******', authority: 'https://login.microsoftonline.com/*****/', validateAuthority: true, redirectUri: 'http://localhost:4200/', postLogoutRedirectUri: 'http://localhost:4200/', navigateToLoginRequestUrl: true, }, cache: { cacheLocation: 'localStorage', storeAuthStateInCookie: isIE, // set to true for IE 11 }, }, { popUp: !isIE, consentScopes: [ 'user.read', 'openid', 'profile', 'api://**********/access_as_user' ], unprotectedResources: ['https://www.microsoft.com/en-us/'], protectedResourceMap, extraQueryParameters: {} } ) ], declarations: [ ], providers: [ MsalLoginService, { provide: HTTP_INTERCEPTORS, useClass: MsalInterceptor, multi: true } ] }) export class MsalLoginModule { }
受Angular版本限制,我使用的是msal-angular@1.1.2,我的业务代码如下:
@Injectable({ providedIn: 'root' }) export class MsalLoginService { loginDisplay = false; constructor( private broadcastService: BroadcastService, private authService: MsalService ) { this.checkoutAccount(); this.authService.handleRedirectCallback((authError, response) => { if (authError) { console.error('Redirect Error: ', authError.errorMessage); return; } console.log('Redirect Success: ', response); }); this.authService.setLogger(new Logger((logLevel, message, piiEnabled) => { console.log('MSAL Logging: ', message); }, { correlationId: CryptoUtils.createNewGuid(), piiLoggingEnabled: false })); } checkoutAccount() { this.loginDisplay = !!this.authService.getAccount(); } loginPopup(): Observable<any> { return new Observable((subscriber) => { this.authService.loginPopup({ scopes: ['user.read'], prompt: 'select_account' }).then(res => { this.authService.acquireTokenSilent({ scopes: ['user.read'] }).then((response: any) => { // send token for validation on server subscriber.next(response); }).catch(ex => subscriber.error(ex)); }).catch(ex => subscriber.error(ex)); }); } logout() { this.authService.logout(); } }
虽然我认为问题出在Azure的配置中,但还是附上代码供参考。
补充说明:通过Azure门户强制多因素登录的方式有多种,但大部分仅向付费/试用账户开放相关功能。
内容的提问来源于stack exchange,提问作者Michael Razgoner
相关产品推荐
相关产品推荐

