You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ALB与Cognito集成问题:缺少Id Token

ALB与Cognito集成后请求无OIDC令牌导致401的排查方向

问题背景

将Spring Boot应用部署为ECS服务,置于Application Load Balancer(ALB)之后,使用ALB内置功能与AWS Cognito用户池集成认证。用户认证成功后,ALB重定向到应用端点的请求中未包含任何OIDC令牌(id token、access token均缺失),最终请求返回401未授权。

浏览器追踪的请求序列

  1. 请求/authorize
REQUEST :
GET https://dev.auth.example.com/oauth2/authorize?client_id=ql98sh20guvkcktbkmb651so7&redirect_uri=https://app.example.com/oauth2/idpresponse&response_type=code&scope=openid&state=cMnSPDepIyWFnpPAUxPrwpDhn8dW2TWqkVOaBlXTKOXnEHIgBpcU++pPbKoR8EFG0f8J3ebyk9QLCUhvk95zhHKBaC89ZW2sLjKUOMvpVh0J3wUOD7KNNtou6Fwg86RX2UgKXp4o5kFMpCpqJE6e00wQ4Tfh2eOWxt5oT7hRPRJaRbrjlKFd/zDavWm4kg2lO/Vd4uRKpI8em69GivH9etFhfET5c6jF5GnliI25yqZEblxZkZNk9f/EuiM=

RESPONSE :
HTTP/2 302 Found
content-length: 0
location: https://dev.auth.example.com/login?client_id=ql98sh20guvkcktbkmb651so7&redirect_uri=https%3A%2F%2Fapp.example.com%2Foauth2%2Fidpresponse&response_type=code&scope=openid&state=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  1. 请求GET /login
REQUEST :
scheme : https
host : dev.auth.example.com
filename : /login
client_id : ql98sh20guvkcktbkmb651so7
redirect_uri : https://app.example.com/oauth2/idpresponse
response_type : code
scope : openid
state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

RESPONSE :
HTTP OK. (Hosted Login UI displayed)
  1. 请求POST /login
REQUEST :
client_id : ql98sh20guvkcktbkmb651so7
redirect_uri : https://app.example.com/oauth2/idpresponse
response_type : code
scope : openid
state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

RESPONSE :
HTTP/2 302 Found
content-length: 0
location: https://app.example.com/oauth2/idpresponse?code=2a5b9b1d-06ea-4312-98be-f065ca4cd4ad&state=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
date: Fri, 30 Jun 2023 10:25:43 GMT
  1. 请求/oauth2/idpresponse
REQUEST :
GET 
scheme : https
host : app.example.com
filename : /oauth2/idpresponse
code : 2a5b9b1d-06ea-4312-98be-f065ca4cd4ad
state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

RESPONSE :
HTTP/2 302 Found
server: awselb/2.0
date: Fri, 30 Jun 2023 10:25:43 GMT
content-type: text/html
content-length: 110
location: https://app.example.com/home
set-cookie: AWSELBAuthSessionCookie-0=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx; Expires=Fri, 07 Jul 2023 10:25:43 GMT; Path=/; Secure; HttpOnly
set-cookie: AWSELBAuthSessionCookie-1=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx; Expires=Fri, 07 Jul 2023 10:25:43 GMT; Path=/; Secure; HttpOnly
  1. 请求原始API URL /home
REQUEST
GET
scheme : https
host : app.example.com
filename : /home
Address : 15.xxx.xxx.xxx:443

RESPONSE :
Status : 401
Unauthorized : VersionHTTP/2
Transferred759 B (0 B size)
Referrer Policystrict-origin-when-cross-origin

REQUEST HEADERS :
GET /home HTTP/2
Host: app.example.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/114.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: https://dev.auth.example.com/
Connection: keep-alive
Cookie: AWSALBAuthNonce=PIGF4TiUMQH3XYfl; AWSELBAuthSessionCookie-0=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-site
Sec-Fetch-User: ?1
Pragma: no-cache
Cache-Control: no-cache

异常点说明

原本预期步骤4与步骤5之间会触发Token Endpoint请求,且步骤5的请求应携带Auth Tokens。目前/idpResponse返回的AWSELBAuthSessionCookie表明用户已认证成功,但请求/home仍返回401。

排查方向

  • 检查ALB认证规则配置:确认是否开启OIDC令牌注入请求头的选项,ALB默认不会自动传递令牌,需在认证动作中明确配置X-Amzn-Oidc-IdToken、X-Amzn-Oidc-AccessToken等头信息的转发。
  • 验证Cognito应用客户端配置:确保客户端授权类型包含Authorization Code Flow,回调URL(https://app.example.com/oauth2/idpresponse)配置正确,且已开启令牌颁发权限。
  • 检查ALB目标组与转发规则:确认目标组转发规则关联了正确的认证策略,无额外路由拦截令牌传递;同时验证ALB是否将所有必要头信息(含注入的令牌头)转发至后端ECS服务。
  • 查看CloudWatch日志:检查ALB访问日志,确认其是否成功从Cognito获取令牌;查看Cognito用户池日志,排查令牌颁发过程是否存在异常。
  • 验证Spring Boot应用配置:确认应用是否正确配置了从请求头提取OIDC令牌的逻辑,比如是否引入spring-security-oauth2-resource-server依赖,并配置了正确的Cognito JWKS验证端点,避免因应用未识别令牌导致401。
  • 检查Cookie属性:确认AWSELBAuthSessionCookie的Path为/、域名与应用域名匹配,避免后续请求无法携带该Cookie导致ALB重新触发认证。

内容的提问来源于stack exchange,提问作者Mandar K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 14:14:58