You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过SignUp方法给新AWS Cognito用户发送验证邮件?

解决AWS Cognito注册后未发送邮箱验证邮件的问题

一、先检查用户池及应用客户端的配置

这是最常见的触发失败原因,需优先确认配置合规:

  • 启用邮箱验证规则:进入Cognito用户池 → 「MFA和验证」 → 「验证方式」,勾选「邮箱」并设置「验证邮件」为必填项,确保开启“用户注册后需验证邮箱”的规则。
  • 配置邮件发送渠道:在用户池「邮件设置」中,确认已配置有效发送源(支持Cognito默认邮件服务或关联AWS SES),且验证邮件模板包含正确的验证码/验证链接。
  • 校验应用客户端权限:找到对应ClientId的应用客户端,确认:
    • 若为前端/移动端等公共客户端,不要勾选「生成客户端密钥」;
    • 客户端默认允许注册流程,若有自定义权限配置需确保未限制相关操作。

二、调整代码逻辑(分两种业务场景)

根据你需要的注册流程,提供两种实现方案:

场景1:保持用户自助注册流程(自行设密,验证邮箱后直接登录)

当前SignUpCommand本应自动触发验证邮件,若未触发可添加手动重发逻辑,同时增加邮箱格式校验:

import { CognitoIdentityProviderClient, SignUpCommand, ResendConfirmationCodeCommand } from "@aws-sdk/client-cognito-identity-provider"

const UserPoolId = "你的用户池ID";
const ClientId = "你的客户端ID";
const region = "你的区域"

const config = { region: region }

export const registerUser = async (req, res) => {
    try {
        const { username, password } = req.body;

        // 校验用户名是否为合法邮箱格式
        const emailRegex = /^[^\s@]+@[^\s@]+\.[^\s@]+$/;
        if (!emailRegex.test(username)) {
            return res.status(400).json({ message: "用户名必须是合法邮箱格式" });
        }

        const client = new CognitoIdentityProviderClient(config);
    
        const signUpCommand = new SignUpCommand({
            ClientId: ClientId,
            Username: username,
            Password: password,
            UserAttributes: [{ Name: "email", Value: username }],
            ForceAliasCreation: false
        });
        const response = await client.send(signUpCommand);

        // 若SignUp成功但用户未确认,手动触发重发验证邮件
        if (response.UserConfirmed === false) {
            const resendCommand = new ResendConfirmationCodeCommand({
                ClientId: ClientId,
                Username: username
            });
            await client.send(resendCommand);
        }

        res.status(200).json({ 
            message: "用户创建成功,验证邮件已发送", 
            username: username 
        });
    }
    catch (err) {
        console.error("注册失败:", err.message);
        res.status(500).json({ 
            message: "用户创建失败", 
            error: err.message
        });
    }
};

场景2:实现管理员创建用户流程(与AWS UI一致,用户需重置密码后登录)

如果想要和AWS后台添加用户完全一致的效果(自动发送密码重置邮件,用户必须重置密码才能登录),需替换为AdminCreateUserCommand:

import { CognitoIdentityProviderClient, AdminCreateUserCommand } from "@aws-sdk/client-cognito-identity-provider"

const UserPoolId = "你的用户池ID";
const ClientId = "你的客户端ID";
const region = "你的区域"

const config = { region: region }

export const registerUser = async (req, res) => {
    try {
        const { username } = req.body;

        // 校验邮箱格式
        const emailRegex = /^[^\s@]+@[^\s@]+\.[^\s@]+$/;
        if (!emailRegex.test(username)) {
            return res.status(400).json({ message: "用户名必须是合法邮箱格式" });
        }

        const client = new CognitoIdentityProviderClient(config);
    
        const command = new AdminCreateUserCommand({
            UserPoolId: UserPoolId,
            Username: username,
            UserAttributes: [{ Name: "email", Value: username }],
            // 发送密码重置邮件,用户需设置新密码才能登录
            MessageAction: "RESEND",
            DesiredDeliveryMediums: ["EMAIL"]
        });
        const response = await client.send(command);

        res.status(200).json({ 
            message: "用户创建成功,密码重置邮件已发送", 
            username: username 
        });
    }
    catch (err) {
        console.error("注册失败:", err.message);
        res.status(500).json({ 
            message: "用户创建失败", 
            error: err.message
        });
    }
};

三、关键注意点

  • 自助注册(SignUp)和管理员创建用户(AdminCreateUser)是完全独立的流程:前者由用户自行设置密码,验证邮箱后直接登录;后者由管理员发起,用户需重置密码后才能登录。
  • 确保执行代码的IAM角色拥有对应权限:使用SignUp需cognito-idp:SignUp权限,使用AdminCreateUser需cognito-idp:AdminCreateUser权限。
  • 若仍未收到邮件,检查目标邮箱是否被Cognito拒收,或邮件被归类至垃圾邮件文件夹。

内容的提问来源于stack exchange,提问作者ENV

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 12:03:30