使用AWS CDK创建Cognito授权器时遇ProviderARNs不能为空错误
问题描述
我尝试用AWS CDK创建Cognito授权器,代码如下:
const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', { restApiId: api.restApiId, cognitoUserPools: ["xx-xx1_xxxxx"], type: 'COGNITO_USER_POOLS', name: "AWS", providerARNs: ['arn:aws:cognito-idp:xx-xxxx-1:xxxxxxxxxx:userpool/xx-xxx_xxxxxx'], // userPoolArn is userPool.arn value identitySource: 'method.request.header.Authorization', });
我已经反复核对用户池名称、ARN,也对比了各类示例代码,但始终报“ProviderARNs cannot be empty”错误,实在找不到解决办法了。
解决方案
问题出在你同时指定了cognitoUserPools和providerARNs两个参数,CDK内部处理时会出现冲突,导致providerARNs被清空。
- 正确做法二选一:
- 只保留
cognitoUserPools,注意这里需要传入Cognito User Pool对象,而非字符串形式的用户池ID。如果是引用现有用户池,用UserPool.fromUserPoolId()方法获取对象后传入:// 示例:引用现有用户池 const existingUserPool = apigateway.UserPool.fromUserPoolId(this, 'ExistingUserPool', 'xx-xx1_xxxxx'); const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', { restApiId: api.restApiId, cognitoUserPools: [existingUserPool], name: "AWS", identitySource: 'method.request.header.Authorization', }); - 只保留
providerARNs,删除cognitoUserPools参数,确保ARN格式正确(你当前的ARN格式没问题):const cognitoAuthorizer = new apigateway.CognitoUserPoolsAuthorizer(this, 'rest-api-cognito-authorizer', { restApiId: api.restApiId, name: "AWS", providerARNs: ['arn:aws:cognito-idp:xx-xxxx-1:xxxxxxxxxx:userpool/xx-xxx_xxxxxx'], identitySource: 'method.request.header.Authorization', });
- 只保留
另外,type参数可以省略,因为CognitoUserPoolsAuthorizer默认类型就是COGNITO_USER_POOLS,无需手动指定。
内容的提问来源于stack exchange,提问作者Vivek
相关产品推荐
相关产品推荐

