如何通过Terraform启用AWS Cognito用户名登录功能?
问题描述
使用Terraform创建AWS Cognito用户池时,想要启用用户名登录选项,设置username_attributes = ["username"]后报错:
Error: expected username_attributes.0 to be one of [phone_number email], got username
但AWS控制台中确实存在用户名登录的选项,原代码如下:
resource "aws_cognito_user_pool" "pool" { name = "User_Pool_demo" username_attributes = ["username"] username_configuration { case_sensitive = false } schema { attribute_data_type = "String" mutable = true name = "username" required = true string_attribute_constraints { min_length = 1 max_length = 2048 } } }
解决方案
Terraform的aws_cognito_user_pool资源中,username_attributes字段的作用是指定可替代用户名的登录标识(比如用邮箱或手机号登录),它的可选值仅为phone_number和email,因此不能填入username。
而控制台里的“用户名登录”是Cognito用户池的默认行为——当不配置username_attributes时,用户池默认允许使用用户名登录。你已经在schema中定义了必填的username属性,这正好满足用户名登录的需求。
修正后的代码只需移除错误的username_attributes配置:
resource "aws_cognito_user_pool" "pool" { name = "User_Pool_demo" username_configuration { case_sensitive = false } schema { attribute_data_type = "String" mutable = true name = "username" required = true string_attribute_constraints { min_length = 1 max_length = 2048 } } }
配置完成后,用户池将启用用户名登录,同时你可以通过username_configuration控制用户名的大小写敏感性,完全匹配控制台的配置效果。
内容的提问来源于stack exchange,提问作者Misgav Ngaithe
相关产品推荐
相关产品推荐

