You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS Amplify PubSub访问IoT Core时认证用户触发NotAuthorizedException

解决AWS Amplify PubSub认证用户访问IoT Core的NotAuthorizedException错误

以下是针对该问题的核心排查和修复步骤:

  • 检查认证角色的信任关系
    这是最常见的触发原因:身份池的认证角色信任策略未正确关联你的Cognito用户池。确保信任策略中包含用户池作为联邦身份提供者,且条件匹配认证用户的身份属性:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "cognito-idp.REGION.amazonaws.com/YOUR_USER_POOL_ID"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "cognito-idp.REGION.amazonaws.com/YOUR_USER_POOL_ID:aud": "YOUR_APP_CLIENT_ID"
            },
            "ForAnyValue:StringLike": {
              "cognito-idp.REGION.amazonaws.com/YOUR_USER_POOL_ID:amr": "authenticated"
            }
          }
        }
      ]
    }
    

    替换其中的REGION、YOUR_USER_POOL_ID、YOUR_APP_CLIENT_ID为你实际的配置值。

  • 验证认证角色的IoT权限策略
    确认认证角色的IAM权限策略包含所需的IoT操作(如iot:Publish、iot:Connect等),且资源范围覆盖你要使用的Topic和客户端ID。推荐用用户身份ID作为客户端ID变量,提升安全性:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "iot:Publish",
            "iot:Subscribe",
            "iot:Receive",
            "iot:Connect"
          ],
          "Resource": [
            "arn:aws:iot:REGION:ACCOUNT_ID:topic/your/topic/path/*",
            "arn:aws:iot:REGION:ACCOUNT_ID:client/${cognito-identity.amazonaws.com:sub}"
          ]
        }
      ]
    }
    
  • 核对身份池的身份提供者配置
    进入IAM身份池控制台,确认认证提供者列表中你的Cognito用户池配置无误:用户池ID、应用客户端ID与实际值一致,区域匹配。

  • 检查Amplify客户端配置
    确认前端项目的aws-exports.js(或amplifyconfiguration.json)中,userPoolId、userPoolWebClientId、identityPoolId完全匹配控制台配置,无拼写错误或区域不匹配。

  • 验证临时凭证获取
    在代码中添加调试逻辑,打印认证后的临时凭证信息,确认身份ID和角色ARN正确关联到认证角色:

    import { Auth } from 'aws-amplify';
    
    async function checkCredentials() {
      const credentials = await Auth.currentCredentials();
      console.log('Credentials:', credentials);
    }
    

    如果返回的角色是未认证角色,说明身份池未正确为认证用户分配角色,需重新检查身份池的角色映射配置。

内容的提问来源于stack exchange,提问作者Manjunath N R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 14:52:20