自定义Client Secret创建Cognito应用客户端及权限限制咨询
AWS Cognito保密型应用客户端技术问题解答
我正在使用CloudFormation为Cognito用户池创建保密型应用客户端,对应的CloudFormation资源配置如下:
AppClient: Type: AWS::Cognito::UserPoolClient Properties: ClientName: app-client UserPoolId: !Ref CognitoInfrastructureUserPool EnableTokenRevocation: false AccessTokenValidity: !Ref UserPoolAccessTokenValidity IdTokenValidity: !Ref UserPoolIdTokenValidity RefreshTokenValidity: !Ref UserPoolRefreshTokenValidity TokenValidityUnits: AccessToken: "hours" RefreshToken: "hours" IdToken: "hours" SupportedIdentityProviders: - COGNITO CallbackURLs: !Split [",", !Ref UserPoolCallbackUrls] LogoutURLs: !If - HasLogoutUrls - !Split [ ",", !Ref UserPoolLogoutUrls ] - !Ref AWS::NoValue AllowedOAuthFlowsUserPoolClient: true AllowedOAuthFlows: - code - implicit AllowedOAuthScopes: - phone - email - openid - profile - aws.cognito.signin.user.admin ExplicitAuthFlows: - ALLOW_CUSTOM_AUTH - ALLOW_USER_SRP_AUTH - ALLOW_REFRESH_TOKEN_AUTH PreventUserExistenceErrors: ENABLED ReadAttributes: - address - birthdate WriteAttributes: - address - birthdate GenerateSecret: true
问题解答
是否可使用自行生成的client_secret替代Cognito自动生成的密钥?
不行。Cognito用户池应用客户端的client_secret仅支持由Cognito自动生成,没有配置项允许传入自定义密钥。当设置GenerateSecret: true时,Cognito会自动生成唯一的客户端密钥,无法替换为自定义值。是否能限制仅特定角色的AWS用户可访问该client_secret?
可以。通过IAM策略控制对cognito-idp:DescribeUserPoolClientAPI操作的权限即可,该操作会返回包含client_secret的客户端详情。
示例IAM策略如下(需替换占位符为实际值):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "cognito-idp:DescribeUserPoolClient", "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID/client/CLIENT_ID", "Principal": { "AWS": "arn:aws:iam::ACCOUNT_ID:role/YOUR_SPECIFIC_ROLE" } }, { "Effect": "Deny", "Action": "cognito-idp:DescribeUserPoolClient", "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID/client/CLIENT_ID", "NotPrincipal": { "AWS": "arn:aws:iam::ACCOUNT_ID:role/YOUR_SPECIFIC_ROLE" } } ] }
也可以将权限策略直接附加到目标IAM角色或用户上,仅授予他们访问该客户端密钥的权限。
内容的提问来源于stack exchange,提问作者Chamila Wijayarathna
相关产品推荐
相关产品推荐

