You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中配置Cognito属性验证与用户账户确认

在Terraform中配置Cognito用户池的属性验证与账户确认

以下是我原本用于创建Cognito用户池的Terraform脚本:

resource "aws_cognito_user_pool" "user_pool" {
  name = "${var.app_name}-user-pool"

  username_attributes = ["email"]

  verification_message_template {
    default_email_option = "CONFIRM_WITH_CODE"
    email_subject        = "Account Confirmation"
    email_message        = "Your confirmation code is {####}"
  }
}

resource "aws_cognito_user_pool_client" "client" {
  name = "${var.app_name}-cognito-client"

  user_pool_id                  = aws_cognito_user_pool.user_pool.id
  generate_secret               = false
  refresh_token_validity        = 90
  prevent_user_existence_errors = "ENABLED"
  explicit_auth_flows = [
    "ALLOW_REFRESH_TOKEN_AUTH",
    "ALLOW_USER_PASSWORD_AUTH",
    "ALLOW_ADMIN_USER_PASSWORD_AUTH",
    "ALLOW_CUSTOM_AUTH",
    "ALLOW_USER_SRP_AUTH"
  ]

}

resource "aws_cognito_user_pool_domain" "cognito-domain" {
  domain       = "${var.app_name}userpooldomain"
  user_pool_id = aws_cognito_user_pool.user_pool.id
}

此前我手动配置了属性验证与用户账户确认,现在需要将这些配置整合到上述Terraform脚本中。


修改后的完整脚本

resource "aws_cognito_user_pool" "user_pool" {
  name = "${var.app_name}-user-pool"

  username_attributes = ["email"]
  # 配置自动验证的属性(账户确认环节)
  auto_verified_attributes = ["email"]
  # 允许用于创建账户的属性列表
  account_creation_allow_list = ["email"]

  # 账户确认规则配置
  account_confirmation_settings {
    allow_admin_create_user_only = false
    code_validity_units = "MINUTES"
    code_validity_length = 60
    send_account_confirmation_message = true
  }

  # 用户属性验证规则定义
  schema {
    name                = "email"
    attribute_data_type = "String"
    mutable             = true
    required            = true

    # 邮箱属性的验证约束
    attribute_constraints {
      min_length = "6"
      max_length = "256"
      pattern    = "^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$"
    }
  }

  verification_message_template {
    default_email_option = "CONFIRM_WITH_CODE"
    email_subject        = "Account Confirmation"
    email_message        = "Your confirmation code is {####}"
  }
}

resource "aws_cognito_user_pool_client" "client" {
  name = "${var.app_name}-cognito-client"

  user_pool_id                  = aws_cognito_user_pool.user_pool.id
  generate_secret               = false
  refresh_token_validity        = 90
  prevent_user_existence_errors = "ENABLED"
  explicit_auth_flows = [
    "ALLOW_REFRESH_TOKEN_AUTH",
    "ALLOW_USER_PASSWORD_AUTH",
    "ALLOW_ADMIN_USER_PASSWORD_AUTH",
    "ALLOW_CUSTOM_AUTH",
    "ALLOW_USER_SRP_AUTH"
  ]

}

resource "aws_cognito_user_pool_domain" "cognito-domain" {
  domain       = "${var.app_name}userpooldomain"
  user_pool_id = aws_cognito_user_pool.user_pool.id
}

关键配置说明

  • auto_verified_attributes:指定自动触发验证的用户属性,这里设置为email,用户注册后会自动发送验证邮件完成账户确认。
  • account_confirmation_settings:配置账户确认的细节,包括确认码有效期、是否仅允许管理员创建用户等。
  • schema 块:定义用户属性的验证规则,这里针对email属性设置了长度限制和格式正则校验,实现属性验证需求。你可以根据实际业务需要添加更多属性(如手机号)的验证规则。

内容的提问来源于stack exchange,提问作者Pablo Salazar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 06:42:29