ALB集成Cognito登出功能失效,调整会话超时后遇CORS问题
问题:Cognito登出后仍可免登录访问,调整ALB会话超时后引发POST请求CORS错误
问题背景
已实现Cognito正常登录,但执行标准登出步骤(调用admin_user_global_sign_out、删除ALB Cookie、重定向到Cognito登出URL)后,用户仍能免登录访问网站,流程无报错、重定向正常。
后端FastAPI的/sign_out路由代码如下:
@app.get("/sign_out") async def sign_out(request: Request, response: Response): cognito = boto3.client('cognito-idp', region_name=<region_name>) headers = request.headers identity = headers['x-amzn-oidc-identity'] cognito.admin_user_global_sign_out( UserPoolId=<user pool ID>, Username=identity ) response.set_cookie( key="AWSALB", value="-", httponly=False, max_age=0 ) response.set_cookie( key="AWSELBAuthSessionCookie-0", value="-", httponly=False, max_age=0 ) response.set_cookie( key="AWSELBAuthSessionCookie-1", value="-", httponly=False, max_age=0 ) response.set_cookie( key="AWSALBCORS", value="-", httponly=False, max_age=0 ) response.set_cookie( key="AWSALBAuthNonce", value="-", httponly=False, max_age=0 ) return RedirectResponse(url="https://<domain>.auth.<region>.amazoncognito.com/logout?client_id=<client ID>&logout_uri=https://example.com/")
额外配置信息:
- 应用客户端已将
https://example.com/设为允许登出URL - 应用客户端权限范围包含
aws.cognito.signin.user.admin、email、openid、phone - EC2已分配完整管理员权限
- 使用默认ELB配置
排查更新
将ALB监听器会话超时设为1秒(默认7天)后,登出功能生效,但登录状态下通过fetch发送POST请求时出现CORS错误:
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://<domain>.auth.<region>.amazoncognito.com/oauth2/authorize?etc.etc. {Reason CORS header 'Access-Control-Allow-Origin' missing).
GET请求无此问题,纠结是修复CORS还是调整会话超时并非最优解,寻求合适方案。
最优解决方案:修复登出逻辑,避免依赖ALB会话超时
1. 修正ALB Cookie删除逻辑
当前代码删除Cookie的方式存在错误:
- ALB的认证Cookie(
AWSELBAuthSessionCookie-0/1)默认是HttpOnly属性,后端设置httponly=False无法覆盖原Cookie属性,导致删除无效。 - 正确删除需匹配原Cookie的所有属性(domain、path、secure、httponly),再设置
max_age=0。
修改后的Cookie删除代码:
# 删除AWSELBAuthSessionCookie,严格匹配原Cookie属性 response.set_cookie( key="AWSELBAuthSessionCookie-0", value="", max_age=0, httponly=True, secure=True, # HTTPS环境必须开启 path="/", domain=".example.com" # 匹配ALB配置的Cookie域名 ) response.set_cookie( key="AWSELBAuthSessionCookie-1", value="", max_age=0, httponly=True, secure=True, path="/", domain=".example.com" ) # 其他ALB Cookie同理调整 response.set_cookie( key="AWSALB", value="", max_age=0, httponly=False, secure=True, path="/", domain=".example.com" )
2. 完善Cognito登出URL参数
确保登出URL包含完整参数,且logout_uri和redirect_uri一致(需在应用客户端允许列表内):
logout_url = ( f"https://<domain>.auth.<region>.amazoncognito.com/logout" f"?client_id=<client ID>" f"&logout_uri=https://example.com/" f"&redirect_uri=https://example.com/" ) return RedirectResponse(url=logout_url)
3. 验证admin_user_global_sign_out的有效性
确认x-amzn-oidc-identity获取的用户名与Cognito用户池中的Username一致(若用户用邮箱/手机号登录,需确保identity对应正确的Username):
# 可选:验证用户存在性 users = cognito.list_users( UserPoolId="<user pool ID>", Filter=f'username = "{identity}"' ) if not users['Users']: # 处理用户不存在的异常场景 pass
若坚持使用ALB会话超时方案(不推荐)
如果需要保留ALB会话超时设置,解决POST请求CORS错误:
- 在Cognito应用客户端的App client settings中,将
https://example.com/添加到Allowed CORS origins列表。 - 前端
fetch请求需携带credentials: 'include':
fetch('https://your-api.com/post-endpoint', { method: 'POST', credentials: 'include', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(data) })
- 配置ALB监听器的CORS规则:
- 允许
POST方法加入Allowed Methods - 设置
Access-Control-Allow-Origin为https://example.com/ - 启用
Access-Control-Allow-Credentials
- 允许
总结
优先修复登出逻辑中的Cookie删除问题,这是根本解决方案,避免依赖ALB会话超时带来的CORS副作用和频繁认证跳转的用户体验问题。
内容的提问来源于stack exchange,提问作者tewerty
相关产品推荐
相关产品推荐

