You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义Client Secret创建Cognito应用客户端及权限限制咨询

AWS Cognito保密型应用客户端技术问题解答

我正在使用CloudFormation为Cognito用户池创建保密型应用客户端,对应的CloudFormation资源配置如下:

AppClient:
    Type: AWS::Cognito::UserPoolClient
    Properties:
        ClientName: app-client
        UserPoolId: !Ref CognitoInfrastructureUserPool
        EnableTokenRevocation: false
        AccessTokenValidity: !Ref UserPoolAccessTokenValidity
        IdTokenValidity: !Ref UserPoolIdTokenValidity
        RefreshTokenValidity: !Ref UserPoolRefreshTokenValidity
        TokenValidityUnits:
            AccessToken: "hours"
            RefreshToken: "hours"
            IdToken: "hours"
        SupportedIdentityProviders:
            - COGNITO
        CallbackURLs: !Split [",", !Ref UserPoolCallbackUrls]
        LogoutURLs: !If
            - HasLogoutUrls
            - !Split [ ",", !Ref UserPoolLogoutUrls ]
            - !Ref AWS::NoValue
        AllowedOAuthFlowsUserPoolClient: true
        AllowedOAuthFlows:
            - code
            - implicit
        AllowedOAuthScopes:
            - phone
            - email
            - openid
            - profile
            - aws.cognito.signin.user.admin
        ExplicitAuthFlows:
            - ALLOW_CUSTOM_AUTH
            - ALLOW_USER_SRP_AUTH
            - ALLOW_REFRESH_TOKEN_AUTH
        PreventUserExistenceErrors: ENABLED
        ReadAttributes:
            - address
            - birthdate
        WriteAttributes:
            - address
            - birthdate
        GenerateSecret: true

问题解答

  1. 是否可使用自行生成的client_secret替代Cognito自动生成的密钥?
    不行。Cognito用户池应用客户端的client_secret仅支持由Cognito自动生成,没有配置项允许传入自定义密钥。当设置GenerateSecret: true时,Cognito会自动生成唯一的客户端密钥,无法替换为自定义值。

  2. 是否能限制仅特定角色的AWS用户可访问该client_secret?
    可以。通过IAM策略控制对cognito-idp:DescribeUserPoolClient API操作的权限即可,该操作会返回包含client_secret的客户端详情。

示例IAM策略如下(需替换占位符为实际值):

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "cognito-idp:DescribeUserPoolClient",
            "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID/client/CLIENT_ID",
            "Principal": {
                "AWS": "arn:aws:iam::ACCOUNT_ID:role/YOUR_SPECIFIC_ROLE"
            }
        },
        {
            "Effect": "Deny",
            "Action": "cognito-idp:DescribeUserPoolClient",
            "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID/client/CLIENT_ID",
            "NotPrincipal": {
                "AWS": "arn:aws:iam::ACCOUNT_ID:role/YOUR_SPECIFIC_ROLE"
            }
        }
    ]
}

也可以将权限策略直接附加到目标IAM角色或用户上,仅授予他们访问该客户端密钥的权限。


内容的提问来源于stack exchange,提问作者Chamila Wijayarathna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 07:44:57