You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Bot Framework GDPR合规:不使用State Client获取IBotState/IConversations

替代已弃用State Client实现Bot Framework GDPR合规方案

我之前在迁移旧Bot项目到新版本时,也碰到过这个依赖旧State Client的问题,给你分享几个官方推荐的替代方案,完美适配GDPR的数据访问、导出和删除需求:

1. 切换到Bot Framework SDK v4+的状态管理体系

旧的State Client和IBotState接口已经被官方弃用,现在推荐使用基于IStorage抽象层的状态管理系统,核心是UserState、ConversationState这两个类,支持多种存储后端(开发用Memory Storage,生产用Azure Cosmos DB/Blob Storage)。

第一步:配置状态存储

在项目的依赖注入配置中(比如Startup.cs),替换旧的State Client注册:

// 开发环境用Memory Storage(仅测试,重启后数据丢失)
services.AddSingleton<IStorage, MemoryStorage>();

// 生产环境推荐用Azure Cosmos DB(持久化、高可用)
// services.AddSingleton<IStorage>(sp =>
// {
//     var options = new CosmosDbStorageOptions
//     {
//         AuthKey = "你的Cosmos DB密钥",
//         CollectionId = "botstate",
//         CosmosDbEndpoint = new Uri("你的Cosmos DB端点"),
//         DatabaseId = "botdb"
//     };
//     return new CosmosDbStorage(options);
// });

// 注册用户状态和会话状态服务
services.AddSingleton<UserState>();
services.AddSingleton<ConversationState>();

2. 实现GDPR核心操作

基于新的状态管理体系,你可以轻松实现GDPR要求的三个核心功能:

数据访问/导出

通过UserState获取用户的所有状态数据,序列化后返回给用户:

private readonly UserState _userState;
private readonly ConversationState _conversationState;

// 通过构造函数注入状态服务
public GdprController(UserState userState, ConversationState conversationState)
{
    _userState = userState;
    _conversationState = conversationState;
}

public async Task<IActionResult> ExportUserAndConversationData(string userId, string conversationId, ITurnContext turnContext)
{
    // 获取用户状态数据(比如用户配置文件)
    var userProfileAccessor = _userState.CreateProperty<UserProfile>("UserProfile");
    var userProfile = await userProfileAccessor.GetAsync(turnContext, () => new UserProfile());

    // 获取会话状态数据
    var conversationDataAccessor = _conversationState.CreateProperty<ConversationData>("ConversationData");
    var conversationData = await conversationDataAccessor.GetAsync(turnContext, () => new ConversationData());

    // 打包成GDPR导出格式(比如JSON)
    var exportData = new
    {
        UserId = userId,
        UserProfile = userProfile,
        ConversationId = conversationId,
        ConversationData = conversationData
    };

    return Json(exportData);
}

数据删除

直接调用状态服务的DeleteAsync方法,或者通过底层IStorage删除指定的状态记录:

private readonly IServiceProvider _services;

public GdprController(IServiceProvider services)
{
    _services = services;
}

public async Task<IActionResult> DeleteUserData(string userId, ITurnContext turnContext)
{
    var userState = _services.GetRequiredService<UserState>();
    // 删除用户所有状态数据
    await userState.DeleteAsync(turnContext);
    
    // 如果需要删除关联的会话数据,可以遍历该用户的所有会话后删除
    // 或者直接操作IStorage删除匹配userId的记录
    var storage = _services.GetRequiredService<IStorage>();
    var keys = await storage.ListAsync($"user/{userId}/");
    await storage.DeleteAsync(keys);

    return Ok("用户数据已成功删除");
}

3. 替代IConversations的功能

如果需要管理会话相关操作(比如恢复会话、发送消息),现在可以用ConversationReference和BotAdapter来实现,替代旧的IConversations接口:

private readonly IServiceProvider _services;
private readonly IConfiguration _configuration;

public GdprController(IServiceProvider services, IConfiguration configuration)
{
    _services = services;
    _configuration = configuration;
}

public async Task ResumeUserConversation(ConversationReference conversationReference)
{
    var adapter = _services.GetRequiredService<BotAdapter>();
    var appId = _configuration["MicrosoftAppId"];

    await adapter.ContinueConversationAsync(appId, conversationReference, async (turnContext, cancellationToken) =>
    {
        // 在这里执行会话操作,比如通知用户数据已删除
        await turnContext.SendActivityAsync("你的个人数据已按GDPR要求删除");
    }, CancellationToken.None);
}

额外提醒

如果你的项目还在使用Bot Framework SDK v3,官方强烈建议迁移到v4(v3已停止支持)。如果暂时无法迁移,v3中可以使用BotStateService的自定义实现,但稳定性和合规性不如v4的方案。

内容的提问来源于stack exchange,提问作者Leeroy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 07:04:53