You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amplify Cognito生产环境中如何隐藏配置变量?

React/Node.js 生产环境部署:AWS Cognito Amplify 配置暴露问题

我在 React/Node.js 应用中使用 AWS Cognito 实现身份认证,功能运行正常,但部署到生产环境时遇到了 Amplify 配置的暴露问题。我通常通过后端回调来保护环境变量,但不知道如何处理 Amplify 的配置——authConfig 中的相关值总会以某种方式泄露。

当前 App.tsx 中的配置代码:

Amplify.configure({
    Auth: authConfig,
} as any)

尝试方案1:将配置放入 amplifyconfiguration.json 文件

  • 将配置内容写入 amplifyconfiguration.json:
{
  "Cognito": {
    "userPoolId": "value1",
    "userPoolClientId": "value2",
    "identityPoolId": "value3",
    "allowGuestAccess": true,
    "signUpVerificationMethod": "code",
    "loginWith": {
      "oauth": {
        "domain": "value4",
        "scopes": ["email", "username", "aws.cognito.signin.user.admin"],
        "redirectSignIn": ["value5"],
        "redirectSignOut": ["value6"],
        "responseType": "token"
      }
    }
  }
}
  • 在 App.tsx 中导入该配置:
import authConfig from "./amplifyconfiguration.json";
Amplify.configure({Auth: authConfig,} as any)

问题:项目构建后,value1、value2 等值会出现在 dist/assets 文件中。

尝试方案2:通过后端回调获取配置值

  • 从后端接口拉取配置后初始化 Amplify:
this.getValues(...).then(authConfig => {
    Amplify.configure({Auth: authConfig,} as any);
});

问题:value1、value2 等值会出现在回调的响应中(例如 Chrome 控制台的 Network 面板)。

尝试方案3:后端配置 Amplify 后返回实例给前端

  • 思路:在后端直接配置 Amplify,然后将 Amplify 实例返回给前端

问题:不知道如何实现,无法创建 Amplify 或 DefaultAmplify 实例。

内容的提问来源于stack exchange,提问作者vanessa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 01:00:06