在AD B2C自定义策略单个编排步骤中实现邮箱验证码验证
将验证码验证整合到AD B2C自定义策略的第一个编排步骤
要把验证码验证和邮箱收集、发送验证码合并到同一个自断言步骤,你需要调整现有的自断言技术配置文件,并补充验证码验证的逻辑。以下是具体的修改方案:
1. 更新自断言技术配置文件(LocalAccountSignUpWithLogonEmail-FirstStep)
修改后的配置会在同一个页面中先收集邮箱,点击「发送验证码」后显示验证码输入框,输入完成后验证验证码有效性:
<TechnicalProfile Id="LocalAccountSignUpWithLogonEmail-FirstStep"> <DisplayName>Email signup</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="IpAddressClaimReferenceId">IpAddress</Item> <Item Key="ContentDefinitionReferenceId">api.localaccountsignup</Item> <!-- 修改按钮文本为"发送验证码",点击后触发验证码发送 --> <Item Key="language.button_continue">Send verification code</Item> <!-- 启用邮箱验证逻辑,让控件支持验证码输入 --> <Item Key="EnforceEmailVerification">True</Item> <!-- 指定验证码声明的名称,用于绑定输入框 --> <Item Key="VerificationCodeClaimReferenceId">verificationCode</Item> <!-- 设置验证码输入框的提示文本 --> <Item Key="language.verificationCode">Verification Code</Item> <Item Key="language.verificationCodeEnterInstructions">Please enter the verification code sent to your email.</Item> </Metadata> <CryptographicKeys> <Key Id="issuer_secret" StorageReferenceId="B2C_1A_TokenSigningKeyContainer" /> </CryptographicKeys> <InputClaims> <InputClaim ClaimTypeReferenceId="email" /> </InputClaims> <OutputClaims> <!-- 标记邮箱为已验证,关联到Verified.Email --> <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="Verified.Email" Required="true" /> <!-- 用户输入的验证码声明 --> <OutputClaim ClaimTypeReferenceId="verificationCode" Required="true" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CopyEmailAsReadOnly" /> </OutputClaimsTransformations> <ValidationTechnicalProfiles> <!-- 第一步:发送验证码到用户邮箱 --> <ValidationTechnicalProfile ReferenceId="REST-API-SendVerificationEmail" /> <!-- 第二步:验证用户输入的验证码是否有效 --> <ValidationTechnicalProfile ReferenceId="REST-API-VerifyVerificationCode" /> </ValidationTechnicalProfiles> <UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" /> </TechnicalProfile>
关键修改点:
- 将
EnforceEmailVerification设置为True,开启自断言控件的验证码验证流程 - 添加
VerificationCodeClaimReferenceId元数据,指定验证码对应的声明 - 补充验证码相关的语言提示文本,优化用户体验
- 在
ValidationTechnicalProfiles中新增验证码验证的REST技术配置,实现发送+验证的串联逻辑
2. 新增验证码验证的REST技术配置文件(REST-API-VerifyVerificationCode)
你需要新增一个REST技术配置,用于调用后端接口验证用户输入的验证码是否有效:
<TechnicalProfile Id="REST-API-VerifyVerificationCode"> <DisplayName>Verify verification code</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://myweb.azurewebsites.net/api/Identity/VerifyVerificationCode</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> <Item Key="AllowInsecureAuthInProduction">true</Item> <!-- 如果验证失败,返回错误信息给用户 --> <Item Key="ErrorResponseMessageClaimType">verificationCodeError</Item> </Metadata> <InputClaims> <!-- 传递邮箱和用户输入的验证码到验证接口 --> <InputClaim ClaimTypeReferenceId="email" /> <InputClaim ClaimTypeReferenceId="verificationCode" /> </InputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile>
注意事项:
- 你的后端需要实现
VerifyVerificationCode接口,接收邮箱和验证码参数,验证其有效性 - 如果验证失败,接口需要返回包含错误信息的响应,B2C会自动将错误信息展示给用户
- 生产环境中请关闭
AllowInsecureAuthInProduction,改用HTTPS和合适的认证方式
3. 调整原发送验证码的REST技术配置(REST-API-SendVerificationEmail)
原配置可以保持不变,但需要确保你的SendVerificationCode接口生成验证码后,将其与邮箱关联存储(比如存入数据库或缓存),以便后续验证接口可以查询验证:
<TechnicalProfile Id="REST-API-SendVerificationEmail"> <DisplayName>Sign-Up send link</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://myweb.azurewebsites.net/api/Identity/SendVerificationCode</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> <Item Key="AllowInsecureAuthInProduction">true</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="email" /> </InputClaims> <!-- 这里不需要返回verificationCode,因为验证码是用户输入的,后端存储验证 --> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile>
调整说明:
- 移除了
OutputClaims中的verificationCode,因为现在验证码是用户输入的,不需要从发送接口返回 - 发送接口的核心逻辑是生成验证码、发送邮件、并将验证码与邮箱关联存储
这样配置后,用户的流程就变成:
- 在第一个页面输入邮箱,点击「发送验证码」
- B2C调用
REST-API-SendVerificationEmail发送验证码到用户邮箱 - 页面自动显示验证码输入框,用户输入收到的验证码
- B2C调用
REST-API-VerifyVerificationCode验证验证码有效性 - 验证通过后,进入后续的编排步骤
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

