我使用这个MSAL Library (https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/lib/msal-angular)进行身份验证。
对于密码重置,我的代码如下:
// app.component.ts
constructor(private authService: MsalService)
{
if (this.forgotPassword()) {
this.navigateToForgotPassword();
} else {
this.authService
.acquireTokenSilent(MsalHelperService.getMsalConfigurationSettingValue('consentScopes'))
.then(token => {
if (this.authService.getUser()) {
this.userService.setLoggedIn(true);
this.navigateToLandingPage();
} else {
this.userService.setLoggedIn(false);
this.login();
}
})
.catch(error => {
this.userService.setLoggedIn(false);
this.login();
});
}
...
}
// Determine if user clicked "Forgot Password"
forgotPassword() {
const storage = this.authService.getCacheStorage();
const authError: string = storage.getItem('msal.login.error') ? storage.getItem('msal.login.error') : null;
if (authError && authError.indexOf('AADB2C90118') > -1) {
return true;
}
return false;
}
navigateToForgotPassword() {
this.authService.authority = this.authService.authority.replace('b2c_1a_signupsignin', 'b2c_1a_passwordreset');
this.authService.loginRedirect(MsalHelperService.getMsalConfigurationSettingValue('consentScopes'));
}到目前为止,一切都运行良好。
在密码重置之后,用户被定向回app.component,然后调用loginRedirect()来显示登录表单。
返回app.component时,将记录以下错误:
“拒绝在帧中显示'https://...signupsignin/‘,因为它将'X- frame -Options’设置为'deny'”。
理想情况下,我想让用户在密码重置后自动登录。
请告诉我这是否可能,或者至少我可以在不修改MSAL库的情况下摆脱上面的错误。
发布于 2019-02-07 13:34:05
自动登录仍然是一个问题,但我通过在loginSuccess上注销解决了这个错误。
this.loginSuccessSubscription = this.broadcastService.subscribe('msal:loginSuccess', payload => {
// Temporary solution to avoid 'X-Frame-Options' error on password reset. MSAL not yet supporting auto-login after password reset.
if (this.resetPassword()) {
this.logout();
}
...
});
// Check claim
resetPassword() {
return document.referrer.toLowerCase().indexOf('b2c_1a_passwordreset') > -1;
}发布于 2019-02-07 22:00:11
根据你的回答,我也做了类似的事情:
if (payload._errorDesc && payload._errorDesc.indexOf('AADB2C90118') !== -1) {
console.log('Set recovery flow to true');
console.log('Redirecting to password recovery page');
localStorage.setItem('custom.recovery.password.flow', 'true');
msalService.authority = `https://login.microsoftonline.com/tfp/${environment.tenant}/b2c_1_reset_password/v2.0/`;
msalService.loginRedirect();
}
});
this.broadcastService.subscribe('msal:loginSuccess', payload => {
if(localStorage.getItem('custom.recovery.password.flow') === 'true'){
console.log('Set recovery to false');
console.log('Redirecting to login page');
localStorage.setItem('custom.recovery.password.flow', 'false');
msalService.logout();
}
});https://stackoverflow.com/questions/54285749
复制相似问题