You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C:如何在Refresh_Token流程中调用REST获取最新声明?

解决Azure AD B2C刷新令牌时不更新声明的问题

Great question—this is a super common pain point with Azure AD B2C's refresh token flow, since the default behavior skips most user journey logic to keep things fast and silent. Let's break down your options clearly:

一、修改用户旅程实现刷新时触发REST调用

Absolutely, you can adjust your Identity Experience Framework (IEF) policy to trigger the REST API call during the refresh token flow. Here's how to make it work:

  • Detect the refresh token flow: Azure AD B2C automatically sets a claim isRefreshTokenFlow with value true when handling a refresh token request. Use this to control which orchestration steps run.
  • Adjust step preconditions: By default, steps like your REST API call are skipped during refresh. Modify the preconditions for your REST step so it doesn't skip when isRefreshTokenFlow is true. Example XML snippet for your orchestration step:
    <OrchestrationStep Order="X" Type="ClaimsExchange">
      <Preconditions>
        <!-- Reverse the default skip logic for refresh flow -->
        <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
          <Value>isRefreshTokenFlow</Value>
          <Value>true</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="RESTGetSecurityCredentials" TechnicalProfileReferenceId="REST-AzureFunction-SecurityCreds" />
      </ClaimsExchanges>
    </OrchestrationStep>
    
  • Ensure silent-compatible REST calls: Since refresh happens without user interaction, your Azure Function must fetch credentials using existing claims (like objectId or email) instead of requiring user input. Use HttpRequestMethod="GET" or a non-interactive POST with claims as parameters in your technical profile.
  • Verify token issuance: Double-check your JwtIssuer technical profile to ensure the updated claims from the REST API are included in the new Access/ID tokens via the <OutputClaims> section.

二、无需重新登录的替代方案

If modifying the IEF policy feels too involved, here are two workarounds that avoid full re-authentication:

  • Silent authorization with prompt=none: Instead of calling the refresh token endpoint directly, initiate an authorization request with prompt=none (plus response_type=token id_token, your client ID, redirect URI, etc.). This triggers a silent user journey run, which executes your REST API call and issues updated tokens—no login prompt, as long as the user's B2C session is still valid.
  • App-layer token enrichment: Add middleware to your application (or API gateway) that:
    1. Calls Azure AD B2C's refresh endpoint to get base tokens.
    2. Separately invokes your Azure Function to fetch the latest security credentials.
    3. Attaches these credentials as custom claims to the token (or passes them alongside the token to backend services).
      This keeps B2C policy changes minimal but shifts some logic to your application layer.

Key Considerations

  • Test the refresh flow thoroughly to ensure failed REST calls don't break token refresh (add retry logic or fallback claims in your technical profile if needed).
  • Refresh tokens have a default 7-day lifespan—once expired, the user will have to re-authenticate regardless of your setup.
  • For frequently changing credentials, the silent authorization flow might be more reliable, as it guarantees fresh claims on each token refresh cycle.

内容的提问来源于stack exchange,提问作者tank104

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:47:51