AWS Amplify V6重置新密码登录时遇EmptyChallengeResponse错误
解决AWS Amplify V6登录确认时的EmptyChallengeResponse错误
先搞懂challengeResponse是什么
它是首次调用signIn后返回的会话上下文对象,里面包含Amplify完成后续认证步骤必须的临时会话数据(比如会话ID、当前挑战类型等)。简单说,它是用来把“第一次登录触发新密码要求”和“后续设置新密码确认登录”这两步绑定成同一个认证会话的凭证,没有它Amplify无法识别这是同一个登录流程的延续。
你的代码问题在哪
- confirmSignIn的第三个参数传错了:当signIn返回
CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED时,confirmSignIn需要传入的挑战类型是"NEW_PASSWORD_REQUIRED",而不是登录用的"ALLOW_USER_PASSWORD_AUTH"。 - 逻辑顺序错误:完成新密码确认后,你错误设置了
setRequireNewPassword(true),这会导致后续逻辑混乱——此时已经完成新密码设置,不需要再进入requireNewPassword分支。 - 参数传递细节:虽然你把signInResponse赋值给challengeResponse是对的,但要确保这个对象完整传递给confirmSignIn,Amplify需要从里面读取会话上下文。
修正后的代码
const handleSubmit = async (e) => { e.preventDefault(); try { if (!requireNewPassword) { console.log("[] username", username); console.log("[] password", password); const signInResponse = await signIn({ username, password, options: { authFlowType: "ALLOW_USER_PASSWORD_AUTH" } }); console.log("[] signInResponse", signInResponse); if (signInResponse.nextStep.signInStep === "CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED") { console.log("CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED"); const newPassword = prompt("Please enter your new password:"); if (newPassword) { // signInResponse就是需要的challengeResponse const confirmSignInResponse = await confirmSignIn( signInResponse, newPassword, "NEW_PASSWORD_REQUIRED" // 改为正确的挑战类型 ); console.log("[] user after password change", confirmSignInResponse); setUser(confirmSignInResponse); // 更新用户对象为确认后的结果 navigate("/dashboard"); } else { console.error("New password not provided."); } } else { setUser(signInResponse); navigate("/dashboard"); } } else { const confirmSignInResponse = await confirmSignIn( user, newPassword, "NEW_PASSWORD_REQUIRED" ); console.log("[] user after password change", confirmSignInResponse); setUser(confirmSignInResponse); navigate("/dashboard"); } } catch (error) { setError("Invalid username or password"); console.error("Error:", error); } };
关键修改点
- 将第一个分支中
confirmSignIn的第三个参数从"ALLOW_USER_PASSWORD_AUTH"改为"NEW_PASSWORD_REQUIRED",匹配当前挑战类型。 - 完成新密码确认后,直接设置用户对象并跳转到仪表盘,移除错误的
setRequireNewPassword(true)调用。 - 确保
signInResponse完整传递给confirmSignIn,它就是所需的challengeResponse。
内容的提问来源于stack exchange,提问作者Flavio Andrade
相关产品推荐
相关产品推荐

