Bot Framework GDPR合规:不使用State Client获取IBotState/IConversations
替代已弃用State Client实现Bot Framework GDPR合规方案
我之前在迁移旧Bot项目到新版本时,也碰到过这个依赖旧State Client的问题,给你分享几个官方推荐的替代方案,完美适配GDPR的数据访问、导出和删除需求:
1. 切换到Bot Framework SDK v4+的状态管理体系
旧的State Client和IBotState接口已经被官方弃用,现在推荐使用基于IStorage抽象层的状态管理系统,核心是UserState、ConversationState这两个类,支持多种存储后端(开发用Memory Storage,生产用Azure Cosmos DB/Blob Storage)。
第一步:配置状态存储
在项目的依赖注入配置中(比如Startup.cs),替换旧的State Client注册:
// 开发环境用Memory Storage(仅测试,重启后数据丢失) services.AddSingleton<IStorage, MemoryStorage>(); // 生产环境推荐用Azure Cosmos DB(持久化、高可用) // services.AddSingleton<IStorage>(sp => // { // var options = new CosmosDbStorageOptions // { // AuthKey = "你的Cosmos DB密钥", // CollectionId = "botstate", // CosmosDbEndpoint = new Uri("你的Cosmos DB端点"), // DatabaseId = "botdb" // }; // return new CosmosDbStorage(options); // }); // 注册用户状态和会话状态服务 services.AddSingleton<UserState>(); services.AddSingleton<ConversationState>();
2. 实现GDPR核心操作
基于新的状态管理体系,你可以轻松实现GDPR要求的三个核心功能:
数据访问/导出
通过UserState获取用户的所有状态数据,序列化后返回给用户:
private readonly UserState _userState; private readonly ConversationState _conversationState; // 通过构造函数注入状态服务 public GdprController(UserState userState, ConversationState conversationState) { _userState = userState; _conversationState = conversationState; } public async Task<IActionResult> ExportUserAndConversationData(string userId, string conversationId, ITurnContext turnContext) { // 获取用户状态数据(比如用户配置文件) var userProfileAccessor = _userState.CreateProperty<UserProfile>("UserProfile"); var userProfile = await userProfileAccessor.GetAsync(turnContext, () => new UserProfile()); // 获取会话状态数据 var conversationDataAccessor = _conversationState.CreateProperty<ConversationData>("ConversationData"); var conversationData = await conversationDataAccessor.GetAsync(turnContext, () => new ConversationData()); // 打包成GDPR导出格式(比如JSON) var exportData = new { UserId = userId, UserProfile = userProfile, ConversationId = conversationId, ConversationData = conversationData }; return Json(exportData); }
数据删除
直接调用状态服务的DeleteAsync方法,或者通过底层IStorage删除指定的状态记录:
private readonly IServiceProvider _services; public GdprController(IServiceProvider services) { _services = services; } public async Task<IActionResult> DeleteUserData(string userId, ITurnContext turnContext) { var userState = _services.GetRequiredService<UserState>(); // 删除用户所有状态数据 await userState.DeleteAsync(turnContext); // 如果需要删除关联的会话数据,可以遍历该用户的所有会话后删除 // 或者直接操作IStorage删除匹配userId的记录 var storage = _services.GetRequiredService<IStorage>(); var keys = await storage.ListAsync($"user/{userId}/"); await storage.DeleteAsync(keys); return Ok("用户数据已成功删除"); }
3. 替代IConversations的功能
如果需要管理会话相关操作(比如恢复会话、发送消息),现在可以用ConversationReference和BotAdapter来实现,替代旧的IConversations接口:
private readonly IServiceProvider _services; private readonly IConfiguration _configuration; public GdprController(IServiceProvider services, IConfiguration configuration) { _services = services; _configuration = configuration; } public async Task ResumeUserConversation(ConversationReference conversationReference) { var adapter = _services.GetRequiredService<BotAdapter>(); var appId = _configuration["MicrosoftAppId"]; await adapter.ContinueConversationAsync(appId, conversationReference, async (turnContext, cancellationToken) => { // 在这里执行会话操作,比如通知用户数据已删除 await turnContext.SendActivityAsync("你的个人数据已按GDPR要求删除"); }, CancellationToken.None); }
额外提醒
如果你的项目还在使用Bot Framework SDK v3,官方强烈建议迁移到v4(v3已停止支持)。如果暂时无法迁移,v3中可以使用BotStateService的自定义实现,但稳定性和合规性不如v4的方案。
内容的提问来源于stack exchange,提问作者Leeroy
相关产品推荐
相关产品推荐

