AWS Cognito预认证触发器报错:无法识别Lambda输出,求排查
问题描述
我想在特定场景下抑制access token中的aws.cognito.signin.user.admin权限范围,但认证时触发以下错误:
Error authenticating with Cognito: InvalidLambdaResponseException: Unrecognizable lambda output
我的Lambda函数输出(用户和用户池信息为占位符):
{ "version": "1", "region": "us-east-2", "userPoolId": "userpool", "userName": "id", "callerContext": { "awsSdkVersion": "aws-sdk-nodejs-2.1584.0", "clientId": "clientid" }, "triggerSource": "PreAuthentication_Authentication", "request": { "userAttributes": { "sub": "10aa03fc-d238-45ca-ab7d-6a86942b76c2", "cognito:email_alias": "blah@gmail.com", "cognito:user_status": "CONFIRMED", "email_verified": "true", "name": "Blah", "email": "blah@gmail.com" }, "validationData": null, "userNotFound": false }, "response": { "claimsAndScopeOverrideDetails": { "accessTokenGeneration": { "scopesToAdd": [ "openid" ], "scopesToSuppress": [ "aws.cognito.signin.user.admin" ] } } } }
我的Lambda代码:
export const handler = function(event: any, context: any) { console.log('Received event:', JSON.stringify(event)); // Retrieve user attributes from the event request const userAttributes = event.request.userAttributes; // Construct the response based on the example structure event.response = { "claimsAndScopeOverrideDetails": { "accessTokenGeneration": { "claimsToAddOrOverride": {}, "scopesToAdd": userAttributes['cognito:email_alias'] === 'blah@gmail.com' ? ['openid'] : [], "scopesToSuppress": userAttributes['cognito:email_alias'] === 'blah@gmail.com' ? ['aws.cognito.signin.user.admin'] : [] }, "groupOverrideDetails": {} } }; // Log the constructed response for debugging console.log('Response:', JSON.stringify(event.response)); // Return to Amazon Cognito context.done(null, event); };
问题原因与修复方案
核心错误点
你把范围/声明覆盖逻辑放在了错误的触发器上:PreAuthentication_Authentication触发器不支持claimsAndScopeOverrideDetails这个响应结构,Cognito无法识别该输出,因此抛出InvalidLambdaResponseException。
要修改access token的范围,必须使用Pre Token Generation触发器(对应触发源PreTokenGeneration_Authentication),这个触发器才是专门用来定制JWT令牌内容、添加/抑制范围的。
修复步骤
- 更换触发器类型:在Cognito用户池的触发器设置中,将你的Lambda函数从「Pre Authentication」触发器迁移到「Pre Token Generation」触发器。
- 验证代码逻辑:你的代码本身的范围判断逻辑是正确的,
PreTokenGeneration事件同样包含request.userAttributes字段,无需修改核心代码即可兼容。
额外验证
- 切换触发器后,重新测试认证流程,检查access token的scope字段是否已移除
aws.cognito.signin.user.admin。 - 查看Lambda的CloudWatch日志,确认输出的
event.response结构符合Cognito对Pre Token Generation触发器的要求。
内容的提问来源于stack exchange,提问作者Luke Becker
相关产品推荐
相关产品推荐

