You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略集成Riot Games RSO问题求助

问题:Azure AD B2C自定义策略集成Riot Games登录时回调URI未触发

我正尝试将Riot Games作为身份提供者集成到Azure AD B2C自定义策略中,实现用户通过Riot账号登录应用,但遇到以下问题:

  • 缺乏明确文档,不清楚需向Riot Games发送的元数据内容,无法完成Riot Sign-On(RSO)配置;
  • 调整配置后可跳转至Riot登录页并完成登录,但流程在登录后终止;
  • Riot要求登录完成后回调,我已通过Node.js成功实现该逻辑,但自定义策略未尝试调用指定的回调URI。

当前Claim Provider配置

<TechnicalProfile Id="Riot-OAUTH-Base">
  <DisplayName>Riot Games</DisplayName>
  <Protocol Name="OAuth2" />
  <Metadata>
    <Item Key="ProviderName">riotgames</Item>
    <Item Key="authorization_endpoint">https://auth.riotgames.com/authorize</Item>
    <Item Key="AccessTokenEndpoint">https://auth.riotgames.com/token</Item>
    <Item Key="ClaimsEndpoint">https://auth.riotgames.com/userinfo</Item>
    <Item Key="response_types">code</Item>
    <Item Key="scope">openid offline_access</Item>
    <Item Key="client_id">[clientId]</Item>
  </Metadata>
  <CryptographicKeys>
    <Key Id="client_secret" StorageReferenceId="B2C_1A_RiotGames" />
  </CryptographicKeys>
  <InputClaims />
</TechnicalProfile>

成功实现回调的Node.js代码示例

riotRouter.get('/riot/login', async (c: Context) => {
  const from = c.req.query('from') || '';
  const statePayload = JSON.stringify({ state: generateState(), from });
  let state = Buffer.from(statePayload).toString('base64');
  state = state.replace(/=+$/, ''); 
  console.log('Generated state:', state);
  stateStore.set(state, '1');
  const scope = 'openid offline_access';
  const url =
    `${authUrl}?client_id=${clientId}&redirect_uri=${encodeURIComponent(redirectUri)}&response_type=code&scope=${encodeURIComponent(scope)}&state=${state}`;
  return c.redirect(url);
});

riotRouter.get('/riot/callback', async (c: Context) => {
  const code = c.req.query('code');
  let state = c.req.query('state');
  if (state) state = state.replace(/=+$/, ''); 
  console.log('Received state:', state);

  if (!state || !stateStore.has(state)) {
    console.log('State not found in stateStore');
    return c.text('Invalid state', 400);
  }
  stateStore.delete(state);

  let from = '';
  try {
    const statePayload = JSON.parse(Buffer.from(state, 'base64').toString());
    from = statePayload.from || '';
  } catch (e) {
    from = '';
  }

  // Exchange code for token
  const body = new URLSearchParams();
  body.append('grant_type', 'authorization_code');
  body.append('code', code!);
  body.append('redirect_uri', redirectUri);
  body.append('client_id', clientId);
  body.append('client_secret', clientSecret);

  const tokenResponse = await axios.post(tokenUrl, body.toString(), {
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
  });

  const accessToken = tokenResponse.data.access_token;

  const userInfoResponse = await axios.get('https://auth.riotgames.com/userinfo', {
    headers: { Authorization: `Bearer ${accessToken}` },
  });

  const userInfo = userInfoResponse.data;
  const sub = userInfo.sub;

  const redirectUrl = from
    ? `${from}?access_token=${encodeURIComponent(accessToken)}&sub=${encodeURIComponent(sub)}`
    : `https://httpbin.org/get?access_token=${encodeURIComponent(accessToken)}&sub=${encodeURIComponent(sub)}`;
  return c.redirect(redirectUrl);
});

回调URI未触发的核心原因及解决方法

  1. 未指定redirect_uri元数据
    Azure AD B2C的OAuth2技术配置文件必须明确指定redirect_uri,该地址需与Riot开发者后台配置的回调地址完全一致(格式通常为https://<你的B2C租户>.b2clogin.com/<你的B2C租户>.onmicrosoft.com/oauth2/authresp)。在Riot-OAUTH-Base的<Metadata>节点中添加:
<Item Key="redirect_uri">https://<你的B2C租户>.b2clogin.com/<你的B2C租户>.onmicrosoft.com/oauth2/authresp</Item>
  1. Riot后台回调URI不匹配
    检查Riot开发者控制台中注册的回调地址,确保和B2C策略中redirect_uri完全一致,包括协议、域名、路径,无任何字符差异。

  2. 缺少输出声明与映射
    当前配置未定义<OutputClaims>和<OutputClaimsTransformations>,B2C无法处理Riot返回的用户信息,导致流程终止。需添加对应声明映射:

<OutputClaims>
  <OutputClaim ClaimTypeReferenceId="sub" PartnerClaimType="sub" />
  <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" />
  <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" />
</OutputClaims>
  1. State参数处理不兼容
    你的Node.js代码对state做了移除末尾=的处理,但B2C默认生成的state可能不符合Riot要求。可添加元数据暂时跳过验证(不推荐生产环境),或调整B2C的state生成逻辑:
<Item Key="state_validation_mode">NoValidation</Item>
  1. 遗漏会话管理配置
    需在技术配置文件中添加会话管理引用,维持登录会话:
<UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" />

内容的提问来源于stack exchange,提问作者user20406743

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 03:33:19