You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Cognito预认证触发器报错:无法识别Lambda输出,求排查

问题描述

我想在特定场景下抑制access token中的aws.cognito.signin.user.admin权限范围,但认证时触发以下错误:

Error authenticating with Cognito: InvalidLambdaResponseException: Unrecognizable lambda output

我的Lambda函数输出(用户和用户池信息为占位符):

{
    "version": "1",
    "region": "us-east-2",
    "userPoolId": "userpool",
    "userName": "id",
    "callerContext": {
        "awsSdkVersion": "aws-sdk-nodejs-2.1584.0",
        "clientId": "clientid"
    },
    "triggerSource": "PreAuthentication_Authentication",
    "request": {
        "userAttributes": {
            "sub": "10aa03fc-d238-45ca-ab7d-6a86942b76c2",
            "cognito:email_alias": "blah@gmail.com",
            "cognito:user_status": "CONFIRMED",
            "email_verified": "true",
            "name": "Blah",
            "email": "blah@gmail.com"
        },
        "validationData": null,
        "userNotFound": false
    },
    "response": {
        "claimsAndScopeOverrideDetails": {
            "accessTokenGeneration": {
                "scopesToAdd": [
                    "openid"
                ],
                "scopesToSuppress": [
                    "aws.cognito.signin.user.admin"
                ]
            }
        }
    }
}

我的Lambda代码:

export const handler = function(event: any, context: any) {
    console.log('Received event:', JSON.stringify(event));

    // Retrieve user attributes from the event request
    const userAttributes = event.request.userAttributes;

    // Construct the response based on the example structure
    event.response = {
        "claimsAndScopeOverrideDetails": {
            "accessTokenGeneration": {
                "claimsToAddOrOverride": {},
                "scopesToAdd": userAttributes['cognito:email_alias'] === 'blah@gmail.com' ? ['openid'] : [],
                "scopesToSuppress": userAttributes['cognito:email_alias'] === 'blah@gmail.com' ? ['aws.cognito.signin.user.admin'] : []
            },
            "groupOverrideDetails": {}
        }
    };

    // Log the constructed response for debugging
    console.log('Response:', JSON.stringify(event.response));

    // Return to Amazon Cognito
    context.done(null, event);
};
问题原因与修复方案

核心错误点

你把范围/声明覆盖逻辑放在了错误的触发器上:PreAuthentication_Authentication触发器不支持claimsAndScopeOverrideDetails这个响应结构,Cognito无法识别该输出,因此抛出InvalidLambdaResponseException。

要修改access token的范围,必须使用Pre Token Generation触发器(对应触发源PreTokenGeneration_Authentication),这个触发器才是专门用来定制JWT令牌内容、添加/抑制范围的。

修复步骤

  1. 更换触发器类型:在Cognito用户池的触发器设置中,将你的Lambda函数从「Pre Authentication」触发器迁移到「Pre Token Generation」触发器。
  2. 验证代码逻辑:你的代码本身的范围判断逻辑是正确的,PreTokenGeneration事件同样包含request.userAttributes字段,无需修改核心代码即可兼容。

额外验证

  • 切换触发器后,重新测试认证流程,检查access token的scope字段是否已移除aws.cognito.signin.user.admin。
  • 查看Lambda的CloudWatch日志,确认输出的event.response结构符合Cognito对Pre Token Generation触发器的要求。

内容的提问来源于stack exchange,提问作者Luke Becker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 20:12:37