Azure AD B2C自定义策略集成Riot Games RSO问题求助
问题:Azure AD B2C自定义策略集成Riot Games登录时回调URI未触发
我正尝试将Riot Games作为身份提供者集成到Azure AD B2C自定义策略中,实现用户通过Riot账号登录应用,但遇到以下问题:
- 缺乏明确文档,不清楚需向Riot Games发送的元数据内容,无法完成Riot Sign-On(RSO)配置;
- 调整配置后可跳转至Riot登录页并完成登录,但流程在登录后终止;
- Riot要求登录完成后回调,我已通过Node.js成功实现该逻辑,但自定义策略未尝试调用指定的回调URI。
当前Claim Provider配置
<TechnicalProfile Id="Riot-OAUTH-Base"> <DisplayName>Riot Games</DisplayName> <Protocol Name="OAuth2" /> <Metadata> <Item Key="ProviderName">riotgames</Item> <Item Key="authorization_endpoint">https://auth.riotgames.com/authorize</Item> <Item Key="AccessTokenEndpoint">https://auth.riotgames.com/token</Item> <Item Key="ClaimsEndpoint">https://auth.riotgames.com/userinfo</Item> <Item Key="response_types">code</Item> <Item Key="scope">openid offline_access</Item> <Item Key="client_id">[clientId]</Item> </Metadata> <CryptographicKeys> <Key Id="client_secret" StorageReferenceId="B2C_1A_RiotGames" /> </CryptographicKeys> <InputClaims /> </TechnicalProfile>
成功实现回调的Node.js代码示例
riotRouter.get('/riot/login', async (c: Context) => { const from = c.req.query('from') || ''; const statePayload = JSON.stringify({ state: generateState(), from }); let state = Buffer.from(statePayload).toString('base64'); state = state.replace(/=+$/, ''); console.log('Generated state:', state); stateStore.set(state, '1'); const scope = 'openid offline_access'; const url = `${authUrl}?client_id=${clientId}&redirect_uri=${encodeURIComponent(redirectUri)}&response_type=code&scope=${encodeURIComponent(scope)}&state=${state}`; return c.redirect(url); }); riotRouter.get('/riot/callback', async (c: Context) => { const code = c.req.query('code'); let state = c.req.query('state'); if (state) state = state.replace(/=+$/, ''); console.log('Received state:', state); if (!state || !stateStore.has(state)) { console.log('State not found in stateStore'); return c.text('Invalid state', 400); } stateStore.delete(state); let from = ''; try { const statePayload = JSON.parse(Buffer.from(state, 'base64').toString()); from = statePayload.from || ''; } catch (e) { from = ''; } // Exchange code for token const body = new URLSearchParams(); body.append('grant_type', 'authorization_code'); body.append('code', code!); body.append('redirect_uri', redirectUri); body.append('client_id', clientId); body.append('client_secret', clientSecret); const tokenResponse = await axios.post(tokenUrl, body.toString(), { headers: { 'Content-Type': 'application/x-www-form-urlencoded' }, }); const accessToken = tokenResponse.data.access_token; const userInfoResponse = await axios.get('https://auth.riotgames.com/userinfo', { headers: { Authorization: `Bearer ${accessToken}` }, }); const userInfo = userInfoResponse.data; const sub = userInfo.sub; const redirectUrl = from ? `${from}?access_token=${encodeURIComponent(accessToken)}&sub=${encodeURIComponent(sub)}` : `https://httpbin.org/get?access_token=${encodeURIComponent(accessToken)}&sub=${encodeURIComponent(sub)}`; return c.redirect(redirectUrl); });
回调URI未触发的核心原因及解决方法
- 未指定redirect_uri元数据
Azure AD B2C的OAuth2技术配置文件必须明确指定redirect_uri,该地址需与Riot开发者后台配置的回调地址完全一致(格式通常为https://<你的B2C租户>.b2clogin.com/<你的B2C租户>.onmicrosoft.com/oauth2/authresp)。在Riot-OAUTH-Base的<Metadata>节点中添加:
<Item Key="redirect_uri">https://<你的B2C租户>.b2clogin.com/<你的B2C租户>.onmicrosoft.com/oauth2/authresp</Item>
Riot后台回调URI不匹配
检查Riot开发者控制台中注册的回调地址,确保和B2C策略中redirect_uri完全一致,包括协议、域名、路径,无任何字符差异。缺少输出声明与映射
当前配置未定义<OutputClaims>和<OutputClaimsTransformations>,B2C无法处理Riot返回的用户信息,导致流程终止。需添加对应声明映射:
<OutputClaims> <OutputClaim ClaimTypeReferenceId="sub" PartnerClaimType="sub" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" /> <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> </OutputClaims>
- State参数处理不兼容
你的Node.js代码对state做了移除末尾=的处理,但B2C默认生成的state可能不符合Riot要求。可添加元数据暂时跳过验证(不推荐生产环境),或调整B2C的state生成逻辑:
<Item Key="state_validation_mode">NoValidation</Item>
- 遗漏会话管理配置
需在技术配置文件中添加会话管理引用,维持登录会话:
<UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" />
内容的提问来源于stack exchange,提问作者user20406743
相关产品推荐
相关产品推荐

