You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AD B2C自定义策略单个编排步骤中实现邮箱验证码验证

将验证码验证整合到AD B2C自定义策略的第一个编排步骤

要把验证码验证和邮箱收集、发送验证码合并到同一个自断言步骤,你需要调整现有的自断言技术配置文件,并补充验证码验证的逻辑。以下是具体的修改方案:

1. 更新自断言技术配置文件(LocalAccountSignUpWithLogonEmail-FirstStep)

修改后的配置会在同一个页面中先收集邮箱,点击「发送验证码」后显示验证码输入框,输入完成后验证验证码有效性:

<TechnicalProfile Id="LocalAccountSignUpWithLogonEmail-FirstStep">
  <DisplayName>Email signup</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="IpAddressClaimReferenceId">IpAddress</Item>
    <Item Key="ContentDefinitionReferenceId">api.localaccountsignup</Item>
    <!-- 修改按钮文本为"发送验证码",点击后触发验证码发送 -->
    <Item Key="language.button_continue">Send verification code</Item>
    <!-- 启用邮箱验证逻辑,让控件支持验证码输入 -->
    <Item Key="EnforceEmailVerification">True</Item>
    <!-- 指定验证码声明的名称,用于绑定输入框 -->
    <Item Key="VerificationCodeClaimReferenceId">verificationCode</Item>
    <!-- 设置验证码输入框的提示文本 -->
    <Item Key="language.verificationCode">Verification Code</Item>
    <Item Key="language.verificationCodeEnterInstructions">Please enter the verification code sent to your email.</Item>
  </Metadata>
  <CryptographicKeys>
    <Key Id="issuer_secret" StorageReferenceId="B2C_1A_TokenSigningKeyContainer" />
  </CryptographicKeys>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="email" />
  </InputClaims>
  <OutputClaims>
    <!-- 标记邮箱为已验证,关联到Verified.Email -->
    <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="Verified.Email" Required="true" />
    <!-- 用户输入的验证码声明 -->
    <OutputClaim ClaimTypeReferenceId="verificationCode" Required="true" />
  </OutputClaims>
  <OutputClaimsTransformations>
    <OutputClaimsTransformation ReferenceId="CopyEmailAsReadOnly" />
  </OutputClaimsTransformations>
  <ValidationTechnicalProfiles>
    <!-- 第一步:发送验证码到用户邮箱 -->
    <ValidationTechnicalProfile ReferenceId="REST-API-SendVerificationEmail" />
    <!-- 第二步:验证用户输入的验证码是否有效 -->
    <ValidationTechnicalProfile ReferenceId="REST-API-VerifyVerificationCode" />
  </ValidationTechnicalProfiles>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" />
</TechnicalProfile>

关键修改点:

  • 将EnforceEmailVerification设置为True,开启自断言控件的验证码验证流程
  • 添加VerificationCodeClaimReferenceId元数据,指定验证码对应的声明
  • 补充验证码相关的语言提示文本,优化用户体验
  • 在ValidationTechnicalProfiles中新增验证码验证的REST技术配置,实现发送+验证的串联逻辑

2. 新增验证码验证的REST技术配置文件(REST-API-VerifyVerificationCode)

你需要新增一个REST技术配置,用于调用后端接口验证用户输入的验证码是否有效:

<TechnicalProfile Id="REST-API-VerifyVerificationCode">
  <DisplayName>Verify verification code</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://myweb.azurewebsites.net/api/Identity/VerifyVerificationCode</Item>
    <Item Key="AuthenticationType">None</Item>
    <Item Key="SendClaimsIn">Body</Item>
    <Item Key="AllowInsecureAuthInProduction">true</Item>
    <!-- 如果验证失败,返回错误信息给用户 -->
    <Item Key="ErrorResponseMessageClaimType">verificationCodeError</Item>
  </Metadata>
  <InputClaims>
    <!-- 传递邮箱和用户输入的验证码到验证接口 -->
    <InputClaim ClaimTypeReferenceId="email" />
    <InputClaim ClaimTypeReferenceId="verificationCode" />
  </InputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

注意事项:

  • 你的后端需要实现VerifyVerificationCode接口,接收邮箱和验证码参数,验证其有效性
  • 如果验证失败,接口需要返回包含错误信息的响应,B2C会自动将错误信息展示给用户
  • 生产环境中请关闭AllowInsecureAuthInProduction,改用HTTPS和合适的认证方式

3. 调整原发送验证码的REST技术配置(REST-API-SendVerificationEmail)

原配置可以保持不变,但需要确保你的SendVerificationCode接口生成验证码后,将其与邮箱关联存储(比如存入数据库或缓存),以便后续验证接口可以查询验证:

<TechnicalProfile Id="REST-API-SendVerificationEmail">
  <DisplayName>Sign-Up send link</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="ServiceUrl">https://myweb.azurewebsites.net/api/Identity/SendVerificationCode</Item>
    <Item Key="AuthenticationType">None</Item>
    <Item Key="SendClaimsIn">Body</Item>
    <Item Key="AllowInsecureAuthInProduction">true</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="email" />
  </InputClaims>
  <!-- 这里不需要返回verificationCode,因为验证码是用户输入的,后端存储验证 -->
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

调整说明:

  • 移除了OutputClaims中的verificationCode,因为现在验证码是用户输入的,不需要从发送接口返回
  • 发送接口的核心逻辑是生成验证码、发送邮件、并将验证码与邮箱关联存储

这样配置后,用户的流程就变成:

  1. 在第一个页面输入邮箱,点击「发送验证码」
  2. B2C调用REST-API-SendVerificationEmail发送验证码到用户邮箱
  3. 页面自动显示验证码输入框,用户输入收到的验证码
  4. B2C调用REST-API-VerifyVerificationCode验证验证码有效性
  5. 验证通过后,进入后续的编排步骤

内容的提问来源于stack exchange,提问作者Alex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:40:25