You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略中QR code URI正确但二维码不显示问题

Azure AD B2C自定义策略TOTP二维码无法显示问题

背景

在Azure AD B2C自定义策略中实现TOTP多因素认证(MFA),生成的QR码URI(qrCodeContent)格式符合otpauth://totp/Test:user@example.com?secret=...&issuer=Test的规范,已通过claims bag、日志及二维码生成工具验证。

qrCodeContent示例

otpauth://totp/Test:steveTest@gmail.com?secret=evrg2znbpbyamdo3&issuer=Test&algorithm=SHA1&digits=6&period=30

问题现象

尽管qrCodeContent值完全正确,但在用户旅程的自断言表单上,二维码始终无法显示。

已执行的排查操作

  • 确认claims bag中存在qrCodeContent声明,且值正确无误;
  • 验证二维码对应的DisplayControl(totpQrCodeControl)已完成配置,并在技术配置文件中正确引用;
  • 检查内容定义与页面布局,未发现异常;
  • 浏览器控制台无JavaScript或网络错误;
  • 重新上传并应用策略,排除缓存影响。

相关配置代码

ContentDefinition

<ContentDefinition Id="api.selfasserted.totp">
    <LoadUri>~/tenant/templates/AzureBlue/selfasserted.cshtml</LoadUri>
    <RecoveryUri>~/common/default_page_error.html</RecoveryUri>
    <DataUri>urn:com:microsoft:aad:b2c:elements:contract:selfasserted:1.2.0</DataUri>
    <Metadata>
        <Item Key="DisplayName">TOTP Authenticator Setup</Item>
        <Item Key="IncludeErrorInResponse">true</Item>
    </Metadata>
</ContentDefinition>

Technical Profile

<TechnicalProfile Id="EnableOTPAuthentication">
    <DisplayName>Enable Authenticator app</DisplayName>
    <Protocol Name="Proprietary"
              Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
    <Metadata>
        <Item Key="ContentDefinitionReferenceId">api.selfasserted.totp</Item>
        <Item Key="language.button_continue">Continue</Item>
    </Metadata>
    <CryptographicKeys>
        <Key Id="issuer_secret"
             StorageReferenceId="B2C_1A_TokenSigningKeyContainer" />
    </CryptographicKeys>
    <InputClaimsTransformations>
        <InputClaimsTransformation ReferenceId="CreateSecret" />
        <InputClaimsTransformation ReferenceId="SetTotpIssuer" />
        <InputClaimsTransformation ReferenceId="FormatTotpLabel" />
        <InputClaimsTransformation ReferenceId="CreateQrCodeUri" />
        <!-- same id, new logic -->
    </InputClaimsTransformations>
    <InputClaims>
        <InputClaim ClaimTypeReferenceId="QrCodeScanInstruction"
                    DefaultValue="Scan this QR code with your Authenticator app" />
    </InputClaims>
    <DisplayClaims>
        <DisplayClaim DisplayControlReferenceId="authenticatorAppIconControl" />
        <DisplayClaim ClaimTypeReferenceId="QrCodeScanInstruction" />
        <DisplayClaim DisplayControlReferenceId="totpQrCodeControl" />
        <!-- add this single line -->
        <DisplayClaim DisplayControlReferenceId="authenticatorInfoControl" />
    </DisplayClaims>
    <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="objectId" />
        <OutputClaim ClaimTypeReferenceId="secretKey" />
        <!-- add this so the value is sent to the page -->
        <OutputClaim ClaimTypeReferenceId="qrCodeContent" />
    </OutputClaims>
    <UseTechnicalProfileForSessionManagement ReferenceId="SM-MFA-TOTP" />
</TechnicalProfile>

内容的提问来源于stack exchange,提问作者Ret 2

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 19:45:15