You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AAD B2C自定义本地账户登录策略中添加找回密码链接?

解决方案:在自定义策略中实现带找回密码链接的本地账户登录

嗨Martin,你的需求完全可以实现!咱们分两步解决你遇到的问题:

一、让登录页面显示“Can’t access your account?”链接

你当前的用户旅程缺少处理找回密码请求的分支,且对应的技术配置文件未启用找回链接显示。按以下步骤修改:

1. 启用登录页面的找回密码链接

确保你引用的SelfAsserted-LocalAccountSignin-Email技术配置文件中开启了找回链接。在自定义策略的<ClaimsProviders>部分,找到这个技术配置文件,添加/更新Metadata:

<TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email">
  <Metadata>
    <!-- 保留原有元数据 -->
    <Item Key="showForgotPasswordLink">true</Item>
    <Item Key="userMessageIfClaimsTransformationBooleanValueIsNotEqual">Can't access your account?</Item>
  </Metadata>
  <!-- 保留原有配置 -->
</TechnicalProfile>

2. 修改用户旅程,添加找回密码流程分支

更新你的SignInB2CLocal用户旅程,加入处理找回密码请求的步骤,并调整原有步骤的顺序:

<UserJourney Id="SignInB2CLocal">
  <OrchestrationSteps>
    <OrchestrationStep Order="1" Type="ClaimsProviderSelection" ContentDefinitionReferenceId="api.idpselections">
      <ClaimsProviderSelections>
        <ClaimsProviderSelection TargetClaimsExchangeId="SignInWithLogonNameExchange" />
      </ClaimsProviderSelections>
    </OrchestrationStep>

    <OrchestrationStep Order="2" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="SignInWithLogonNameExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 新增:处理找回密码请求的分支 -->
    <OrchestrationStep Order="3" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
          <Value>isForgotPassword</Value>
          <Value>true</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountPasswordReset-Email" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 原有读取用户信息的步骤调整顺序 -->
    <OrchestrationStep Order="4" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>socialIdpAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <OrchestrationStep Order="5" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
</UserJourney>

3. 确保包含密码重置相关技术配置文件

你的自定义策略需要包含内置的密码重置组件(比如SelfAsserted-LocalAccountPasswordReset-Email、AAD-UserWritePasswordUsingObjectId),这些可以通过继承基础策略(如LocalAccounts)自动获取;如果是从零构建策略,需要手动添加这些配置。

二、关于调用内置策略的令牌验证错误

这个问题通常是应用配置与内置策略不匹配导致的:

  • 确认应用注册中的令牌颁发者URI与内置策略的issuer完全一致(格式类似https://yourtenant.b2clogin.com/yourtenant.onmicrosoft.com/B2C_1_SignIn_Local/v2.0/)
  • 检查应用的签名密钥是否正确配置,确保使用B2C租户提供的密钥
  • 验证令牌逻辑中的受众(Audience)是否与应用的Client ID匹配

不过既然你的目标是用自定义策略复刻内置体验,优先完成上面的自定义策略配置即可。

内容的提问来源于stack exchange,提问作者M Herbener

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:41:51