You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS CDK创建Cognito授权器时遇ProviderARNs不能为空错误

问题描述

我尝试用AWS CDK创建Cognito授权器,代码如下:

const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', {
      restApiId: api.restApiId,
      cognitoUserPools: ["xx-xx1_xxxxx"],
      type: 'COGNITO_USER_POOLS',
      name: "AWS",
      providerARNs: ['arn:aws:cognito-idp:xx-xxxx-1:xxxxxxxxxx:userpool/xx-xxx_xxxxxx'], // userPoolArn is userPool.arn value
      identitySource: 'method.request.header.Authorization',
    });

我已经反复核对用户池名称、ARN,也对比了各类示例代码,但始终报“ProviderARNs cannot be empty”错误,实在找不到解决办法了。

解决方案

问题出在你同时指定了cognitoUserPools和providerARNs两个参数,CDK内部处理时会出现冲突,导致providerARNs被清空。

  • 正确做法二选一:
    1. 只保留cognitoUserPools,注意这里需要传入Cognito User Pool对象,而非字符串形式的用户池ID。如果是引用现有用户池,用UserPool.fromUserPoolId()方法获取对象后传入:
      // 示例:引用现有用户池
      const existingUserPool = apigateway.UserPool.fromUserPoolId(this, 'ExistingUserPool', 'xx-xx1_xxxxx');
      const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', {
        restApiId: api.restApiId,
        cognitoUserPools: [existingUserPool],
        name: "AWS",
        identitySource: 'method.request.header.Authorization',
      });
      
    2. 只保留providerARNs,删除cognitoUserPools参数,确保ARN格式正确(你当前的ARN格式没问题):
      const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', {
        restApiId: api.restApiId,
        name: "AWS",
        providerARNs: ['arn:aws:cognito-idp:xx-xxxx-1:xxxxxxxxxx:userpool/xx-xxx_xxxxxx'],
        identitySource: 'method.request.header.Authorization',
      });
      

另外,type参数可以省略,因为CognitoUserPoolsAuthorizer默认类型就是COGNITO_USER_POOLS,无需手动指定。

内容的提问来源于stack exchange,提问作者Vivek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 04:33:23