Azure AD B2C自定义策略TOTP步骤objectId声明缺失及UI异常问题
Azure AD B2C联系人注册自定义策略TOTP及objectId声明问题
版本差异问题
- 版本2.1.35:TOTP验证码输入表单显示异常,仅出现“qubic”字样,预期的验证码输入框未加载
- 版本2.1.0至2.1.9:验证码输入表单显示正常,但点击“继续”后报错:
租户ID B2C_1A_CONTACTSIGNUP中,指定为标识符声明类型的objectId声明未在声明集合中找到
排查确认结果
通过Application Insights及运行时追踪验证:报错时objectId声明实际存在,故障点AAD-WriteTotpSecret的声明包包含有效objectId值:db6d205e-4a77-4c1c-826b-bea820a3095b
相关配置代码
objectId声明定义
<ClaimType Id="objectId"> <DisplayName>Object ID</DisplayName> <DataType>string</DataType> </ClaimType>
EnableOTPAuthentication技术配置文件
<TechnicalProfile Id="EnableOTPAuthentication"> <OutputClaims> <OutputClaim ClaimTypeReferenceId="objectId" /> <OutputClaim ClaimTypeReferenceId="secretKey" /> <OutputClaim ClaimTypeReferenceId="qrCodeContent" /> <OutputClaim ClaimTypeReferenceId="extension_d370edc869fd4e23ba22efa407bd8935_TOTPSecret" /> </OutputClaims> </TechnicalProfile>
TOTP-Verify技术配置文件
<TechnicalProfile Id="TOTP-Verify"> <DisplayName>Verify Authenticator code</DisplayName> <InputClaims> <InputClaim ClaimTypeReferenceId="userId" /> <InputClaim ClaimTypeReferenceId="otpCode" PartnerClaimType="otpCode" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="extension_d370edc869fd4e23ba22efa407bd8935_TOTPSecret" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="totp" /> </OutputClaims> </TechnicalProfile>
AAD-WriteTotpSecret技术配置文件
<TechnicalProfile Id="AAD-WriteTotpSecret"> <DisplayName>Store TOTP Secret</DisplayName> <InputClaims> <InputClaim ClaimTypeReferenceId="objectId" /> </InputClaims> <PersistedClaims> <PersistedClaim ClaimTypeReferenceId="extension_d370edc869fd4e23ba22efa407bd8935_TOTPSecret" PartnerClaimType="extension_totpSecret" /> </PersistedClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="objectId" /> <OutputClaim ClaimTypeReferenceId="extension_d370edc869fd4e23ba22efa407bd8935_TOTPSecret" /> </OutputClaims> <IncludeTechnicalProfile ReferenceId="AAD-Common" /> </TechnicalProfile>
编排步骤配置
<OrchestrationStep Order="5" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>extension_d370edc869fd4e23ba22efa407bd8935_TOTPSecret</Value> <Value /> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="SaveTotpSecret" TechnicalProfileReferenceId="AAD-WriteTotpSecret" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="6" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="InputTOTPCode" TechnicalProfileReferenceId="SelfAsserted-InputTOTPCode" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="7" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
内容的提问来源于stack exchange,提问作者Ret 2
相关产品推荐
相关产品推荐

