You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Amplify V6重置新密码登录时遇EmptyChallengeResponse错误

解决AWS Amplify V6登录确认时的EmptyChallengeResponse错误

先搞懂challengeResponse是什么

它是首次调用signIn后返回的会话上下文对象,里面包含Amplify完成后续认证步骤必须的临时会话数据(比如会话ID、当前挑战类型等)。简单说,它是用来把“第一次登录触发新密码要求”和“后续设置新密码确认登录”这两步绑定成同一个认证会话的凭证,没有它Amplify无法识别这是同一个登录流程的延续。

你的代码问题在哪

  1. confirmSignIn的第三个参数传错了:当signIn返回CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED时,confirmSignIn需要传入的挑战类型是"NEW_PASSWORD_REQUIRED",而不是登录用的"ALLOW_USER_PASSWORD_AUTH"。
  2. 逻辑顺序错误:完成新密码确认后,你错误设置了setRequireNewPassword(true),这会导致后续逻辑混乱——此时已经完成新密码设置,不需要再进入requireNewPassword分支。
  3. 参数传递细节:虽然你把signInResponse赋值给challengeResponse是对的,但要确保这个对象完整传递给confirmSignIn,Amplify需要从里面读取会话上下文。

修正后的代码

const handleSubmit = async (e) => {
    e.preventDefault();
  
    try {
      if (!requireNewPassword) {
        console.log("[] username", username);
        console.log("[] password", password);
        const signInResponse = await signIn({
          username,
          password,
          options: {
            authFlowType: "ALLOW_USER_PASSWORD_AUTH"
          }
        });
        console.log("[] signInResponse", signInResponse);
  
        if (signInResponse.nextStep.signInStep === "CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED") {
          console.log("CONFIRM_SIGN_IN_WITH_NEW_PASSWORD_REQUIRED");
  
          const newPassword = prompt("Please enter your new password:");
          if (newPassword) {
            // signInResponse就是需要的challengeResponse
            const confirmSignInResponse = await confirmSignIn(
              signInResponse,
              newPassword,
              "NEW_PASSWORD_REQUIRED" // 改为正确的挑战类型
            );
            console.log("[] user after password change", confirmSignInResponse);
            setUser(confirmSignInResponse); // 更新用户对象为确认后的结果
            navigate("/dashboard");
          } else {
            console.error("New password not provided.");
          }
        } else {
          setUser(signInResponse);
          navigate("/dashboard");
        }
      } else {
        const confirmSignInResponse = await confirmSignIn(
          user,
          newPassword,
          "NEW_PASSWORD_REQUIRED"
        );
        console.log("[] user after password change", confirmSignInResponse);
        setUser(confirmSignInResponse);
        navigate("/dashboard");
      }
    } catch (error) {
      setError("Invalid username or password");
      console.error("Error:", error);
    }
  };

关键修改点

  • 将第一个分支中confirmSignIn的第三个参数从"ALLOW_USER_PASSWORD_AUTH"改为"NEW_PASSWORD_REQUIRED",匹配当前挑战类型。
  • 完成新密码确认后,直接设置用户对象并跳转到仪表盘,移除错误的setRequireNewPassword(true)调用。
  • 确保signInResponse完整传递给confirmSignIn,它就是所需的challengeResponse。

内容的提问来源于stack exchange,提问作者Flavio Andrade

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 23:52:09