You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS Cognito SDK创建App Client时遇矛盾错误,请求协助

AWS Cognito App Client OAuth配置参数异常排查

问题描述

已成功创建Cognito用户池App Client,但配置以下参数时遇到矛盾问题:

AllowedOAuthFlows: ["code"],
AllowedAuthScopes: ["phone", "email", "openid", "profile"],
AllowedOAuthFlowsUserPoolClient: true,
  • 省略AllowedOAuthFlowsUserPoolClient时,命令可执行,但Allowed Auth Scopes无法生效
  • 包含该参数时,触发错误:
    InvalidParameterException: AllowedOAuthFlows and AllowedOAuthScopes are required if user pool client is allowed to use OAuth flows.
    

明明请求中已包含AllowedOAuthFlows和AllowedOAuthScopes参数,却仍报错,目标是实现与手动配置App Client一致的效果。

解决方法

  1. 修正参数层级结构
    确保CLI/SDK调用时,OAuth相关参数嵌套在OAuthConfiguration下,而非作为顶级参数传递。比如使用AWS CLI更新客户端:

    aws cognito-idp update-user-pool-client \
      --user-pool-id YOUR_POOL_ID \
      --client-id YOUR_CLIENT_ID \
      --oauth-configuration '{
        "AllowedOAuthFlows": ["code"],
        "AllowedOAuthScopes": ["phone", "email", "openid", "profile"],
        "AllowedOAuthFlowsUserPoolClient": true
      }'
    

    若用Node.js SDK,参数结构需保持一致:

    const params = {
      UserPoolId: 'YOUR_POOL_ID',
      ClientId: 'YOUR_CLIENT_ID',
      OAuthConfiguration: {
        AllowedOAuthFlows: ['code'],
        AllowedOAuthScopes: ['phone', 'email', 'openid', 'profile'],
        AllowedOAuthFlowsUserPoolClient: true
      }
    };
    
  2. 补充必填OAuth参数
    手动配置时Cognito会自动填充默认值,但API调用需明确指定CallbackURLs或LogoutURLs(根据OAuth流程类型)。补充后再执行调用:

    aws cognito-idp update-user-pool-client \
      --user-pool-id YOUR_POOL_ID \
      --client-id YOUR_CLIENT_ID \
      --oauth-configuration '{
        "AllowedOAuthFlows": ["code"],
        "AllowedOAuthScopes": ["phone", "email", "openid", "profile"],
        "AllowedOAuthFlowsUserPoolClient": true,
        "CallbackURLs": ["https://your-app-domain/callback"]
      }'
    
  3. 检查客户端当前配置状态
    先通过命令查看现有客户端的OAuth配置,确认是否存在未初始化或冲突状态:

    aws cognito-idp describe-user-pool-client --user-pool-id YOUR_POOL_ID --client-id YOUR_CLIENT_ID
    

    若此前未配置过OAuth参数,建议通过API完整初始化配置,而非增量更新。

内容的提问来源于stack exchange,提问作者thornberry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 06:21:37