ALB与Cognito集成问题:缺少Id Token
ALB与Cognito集成后请求无OIDC令牌导致401的排查方向
问题背景
将Spring Boot应用部署为ECS服务,置于Application Load Balancer(ALB)之后,使用ALB内置功能与AWS Cognito用户池集成认证。用户认证成功后,ALB重定向到应用端点的请求中未包含任何OIDC令牌(id token、access token均缺失),最终请求返回401未授权。
浏览器追踪的请求序列
- 请求
/authorize
REQUEST : GET https://dev.auth.example.com/oauth2/authorize?client_id=ql98sh20guvkcktbkmb651so7&redirect_uri=https://app.example.com/oauth2/idpresponse&response_type=code&scope=openid&state=cMnSPDepIyWFnpPAUxPrwpDhn8dW2TWqkVOaBlXTKOXnEHIgBpcU++pPbKoR8EFG0f8J3ebyk9QLCUhvk95zhHKBaC89ZW2sLjKUOMvpVh0J3wUOD7KNNtou6Fwg86RX2UgKXp4o5kFMpCpqJE6e00wQ4Tfh2eOWxt5oT7hRPRJaRbrjlKFd/zDavWm4kg2lO/Vd4uRKpI8em69GivH9etFhfET5c6jF5GnliI25yqZEblxZkZNk9f/EuiM= RESPONSE : HTTP/2 302 Found content-length: 0 location: https://dev.auth.example.com/login?client_id=ql98sh20guvkcktbkmb651so7&redirect_uri=https%3A%2F%2Fapp.example.com%2Foauth2%2Fidpresponse&response_type=code&scope=openid&state=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- 请求GET
/login
REQUEST : scheme : https host : dev.auth.example.com filename : /login client_id : ql98sh20guvkcktbkmb651so7 redirect_uri : https://app.example.com/oauth2/idpresponse response_type : code scope : openid state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx RESPONSE : HTTP OK. (Hosted Login UI displayed)
- 请求POST
/login
REQUEST : client_id : ql98sh20guvkcktbkmb651so7 redirect_uri : https://app.example.com/oauth2/idpresponse response_type : code scope : openid state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx RESPONSE : HTTP/2 302 Found content-length: 0 location: https://app.example.com/oauth2/idpresponse?code=2a5b9b1d-06ea-4312-98be-f065ca4cd4ad&state=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx date: Fri, 30 Jun 2023 10:25:43 GMT
- 请求
/oauth2/idpresponse
REQUEST : GET scheme : https host : app.example.com filename : /oauth2/idpresponse code : 2a5b9b1d-06ea-4312-98be-f065ca4cd4ad state : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx RESPONSE : HTTP/2 302 Found server: awselb/2.0 date: Fri, 30 Jun 2023 10:25:43 GMT content-type: text/html content-length: 110 location: https://app.example.com/home set-cookie: AWSELBAuthSessionCookie-0=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx; Expires=Fri, 07 Jul 2023 10:25:43 GMT; Path=/; Secure; HttpOnly set-cookie: AWSELBAuthSessionCookie-1=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx; Expires=Fri, 07 Jul 2023 10:25:43 GMT; Path=/; Secure; HttpOnly
- 请求原始API URL
/home
REQUEST GET scheme : https host : app.example.com filename : /home Address : 15.xxx.xxx.xxx:443 RESPONSE : Status : 401 Unauthorized : VersionHTTP/2 Transferred759 B (0 B size) Referrer Policystrict-origin-when-cross-origin REQUEST HEADERS : GET /home HTTP/2 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/114.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Referer: https://dev.auth.example.com/ Connection: keep-alive Cookie: AWSALBAuthNonce=PIGF4TiUMQH3XYfl; AWSELBAuthSessionCookie-0=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-site Sec-Fetch-User: ?1 Pragma: no-cache Cache-Control: no-cache
异常点说明
原本预期步骤4与步骤5之间会触发Token Endpoint请求,且步骤5的请求应携带Auth Tokens。目前/idpResponse返回的AWSELBAuthSessionCookie表明用户已认证成功,但请求/home仍返回401。
排查方向
- 检查ALB认证规则配置:确认是否开启OIDC令牌注入请求头的选项,ALB默认不会自动传递令牌,需在认证动作中明确配置
X-Amzn-Oidc-IdToken、X-Amzn-Oidc-AccessToken等头信息的转发。 - 验证Cognito应用客户端配置:确保客户端授权类型包含Authorization Code Flow,回调URL(
https://app.example.com/oauth2/idpresponse)配置正确,且已开启令牌颁发权限。 - 检查ALB目标组与转发规则:确认目标组转发规则关联了正确的认证策略,无额外路由拦截令牌传递;同时验证ALB是否将所有必要头信息(含注入的令牌头)转发至后端ECS服务。
- 查看CloudWatch日志:检查ALB访问日志,确认其是否成功从Cognito获取令牌;查看Cognito用户池日志,排查令牌颁发过程是否存在异常。
- 验证Spring Boot应用配置:确认应用是否正确配置了从请求头提取OIDC令牌的逻辑,比如是否引入
spring-security-oauth2-resource-server依赖,并配置了正确的Cognito JWKS验证端点,避免因应用未识别令牌导致401。 - 检查Cookie属性:确认
AWSELBAuthSessionCookie的Path为/、域名与应用域名匹配,避免后续请求无法携带该Cookie导致ALB重新触发认证。
内容的提问来源于stack exchange,提问作者Mandar K
相关产品推荐
相关产品推荐

