You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ALB集成Cognito登出功能失效,调整会话超时后遇CORS问题

问题:Cognito登出后仍可免登录访问,调整ALB会话超时后引发POST请求CORS错误

问题背景

已实现Cognito正常登录,但执行标准登出步骤(调用admin_user_global_sign_out、删除ALB Cookie、重定向到Cognito登出URL)后,用户仍能免登录访问网站,流程无报错、重定向正常。

后端FastAPI的/sign_out路由代码如下:

@app.get("/sign_out")
async def sign_out(request: Request, response: Response):
    
    cognito = boto3.client('cognito-idp', region_name=<region_name>)

    headers = request.headers
    identity = headers['x-amzn-oidc-identity']
    cognito.admin_user_global_sign_out(
        UserPoolId=<user pool ID>,
        Username=identity
    )

    response.set_cookie(
        key="AWSALB",
        value="-",
        httponly=False,
        max_age=0
    )

    response.set_cookie(
        key="AWSELBAuthSessionCookie-0",
        value="-",
        httponly=False,
        max_age=0
    )

    response.set_cookie(
        key="AWSELBAuthSessionCookie-1",
        value="-",
        httponly=False,
        max_age=0
    )

    response.set_cookie(
        key="AWSALBCORS",
        value="-",
        httponly=False,
        max_age=0
    )

    response.set_cookie(
        key="AWSALBAuthNonce",
        value="-",
        httponly=False,
        max_age=0
    )

    return RedirectResponse(url="https://<domain>.auth.<region>.amazoncognito.com/logout?client_id=<client ID>&logout_uri=https://example.com/")

额外配置信息:

  • 应用客户端已将https://example.com/设为允许登出URL
  • 应用客户端权限范围包含aws.cognito.signin.user.admin、email、openid、phone
  • EC2已分配完整管理员权限
  • 使用默认ELB配置

排查更新

将ALB监听器会话超时设为1秒(默认7天)后,登出功能生效,但登录状态下通过fetch发送POST请求时出现CORS错误:

Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://<domain>.auth.<region>.amazoncognito.com/oauth2/authorize?etc.etc. {Reason CORS header 'Access-Control-Allow-Origin' missing).

GET请求无此问题,纠结是修复CORS还是调整会话超时并非最优解,寻求合适方案。


最优解决方案:修复登出逻辑,避免依赖ALB会话超时

1. 修正ALB Cookie删除逻辑

当前代码删除Cookie的方式存在错误:

  • ALB的认证Cookie(AWSELBAuthSessionCookie-0/1)默认是HttpOnly属性,后端设置httponly=False无法覆盖原Cookie属性,导致删除无效。
  • 正确删除需匹配原Cookie的所有属性(domain、path、secure、httponly),再设置max_age=0。

修改后的Cookie删除代码:

# 删除AWSELBAuthSessionCookie,严格匹配原Cookie属性
response.set_cookie(
    key="AWSELBAuthSessionCookie-0",
    value="",
    max_age=0,
    httponly=True,
    secure=True,  # HTTPS环境必须开启
    path="/",
    domain=".example.com"  # 匹配ALB配置的Cookie域名
)
response.set_cookie(
    key="AWSELBAuthSessionCookie-1",
    value="",
    max_age=0,
    httponly=True,
    secure=True,
    path="/",
    domain=".example.com"
)

# 其他ALB Cookie同理调整
response.set_cookie(
    key="AWSALB",
    value="",
    max_age=0,
    httponly=False,
    secure=True,
    path="/",
    domain=".example.com"
)

2. 完善Cognito登出URL参数

确保登出URL包含完整参数,且logout_uri和redirect_uri一致(需在应用客户端允许列表内):

logout_url = (
    f"https://<domain>.auth.<region>.amazoncognito.com/logout"
    f"?client_id=<client ID>"
    f"&logout_uri=https://example.com/"
    f"&redirect_uri=https://example.com/"
)
return RedirectResponse(url=logout_url)

3. 验证admin_user_global_sign_out的有效性

确认x-amzn-oidc-identity获取的用户名与Cognito用户池中的Username一致(若用户用邮箱/手机号登录,需确保identity对应正确的Username):

# 可选:验证用户存在性
users = cognito.list_users(
    UserPoolId="<user pool ID>",
    Filter=f'username = "{identity}"'
)
if not users['Users']:
    # 处理用户不存在的异常场景
    pass

若坚持使用ALB会话超时方案(不推荐)

如果需要保留ALB会话超时设置,解决POST请求CORS错误:

  1. 在Cognito应用客户端的App client settings中,将https://example.com/添加到Allowed CORS origins列表。
  2. 前端fetch请求需携带credentials: 'include':
fetch('https://your-api.com/post-endpoint', {
  method: 'POST',
  credentials: 'include',
  headers: {
    'Content-Type': 'application/json'
  },
  body: JSON.stringify(data)
})
  1. 配置ALB监听器的CORS规则:
    • 允许POST方法加入Allowed Methods
    • 设置Access-Control-Allow-Origin为https://example.com/
    • 启用Access-Control-Allow-Credentials

总结

优先修复登出逻辑中的Cookie删除问题,这是根本解决方案,避免依赖ALB会话超时带来的CORS副作用和频繁认证跳转的用户体验问题。

内容的提问来源于stack exchange,提问作者tewerty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:16:11