You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过CDK创建AWS Cognito用户池时,如何设置标准属性字符串长度?

为AWS Cognito标准属性设置长度限制的解决方案

AWS Cognito的标准属性(如fullname)本身不支持直接通过CDK或AWS原生配置设置最小/最大长度限制,因为Cognito的标准属性定义中未提供这类参数。要实现这个需求,你需要通过Lambda触发器添加自定义验证逻辑。

解决方案:使用Lambda触发器做属性验证

通过Cognito的前置触发器,在用户注册或更新属性时检查fullname的长度,不符合规则则阻止操作。

步骤1:编写验证逻辑的Lambda函数

创建一个Lambda函数,处理Cognito的注册和属性更新事件,验证fullname的长度:

import { PreSignUpTriggerEvent, UpdateUserAttributesTriggerEvent, Callback } from 'aws-lambda';

export const handler = async (
  event: PreSignUpTriggerEvent | UpdateUserAttributesTriggerEvent,
  callback: Callback
) => {
  // 提取fullname(Cognito标准属性fullname对应底层字段为`name`)
  let fullname: string | undefined;
  if ('userAttributes' in event.request) {
    fullname = event.request.userAttributes['name'];
  }

  // 验证长度规则(示例:2-50字符)
  if (fullname) {
    if (fullname.length < 2 || fullname.length > 50) {
      callback(new Error('Fullname must be between 2 and 50 characters'));
      return;
    }
  }

  // 验证通过,传递事件给Cognito
  callback(null, event);
};

步骤2:在CDK中配置用户池并附加触发器

将上述Lambda函数作为Pre Sign-up(注册时)和Update User Attributes(属性更新时)触发器附加到用户池:

import * as lambda from 'aws-cdk-lib/aws-lambda';
import * as cognito from 'aws-cdk-lib/aws-cognito';
import { NodejsFunction } from 'aws-cdk-lib/aws-lambda-nodejs';
import { Construct } from 'constructs';

// 在你的Stack类中:
// 创建验证用Lambda
const validateFullnameLambda = new NodejsFunction(this, 'ValidateFullnameLambda', {
  runtime: lambda.Runtime.NODEJS_20_X,
  entry: './path/to/your/lambda/code.ts', // 替换为实际文件路径
});

// 创建用户池并配置触发器
const userPool = new cognito.UserPool(this, `name-of-user-pool-${stage}`, {
  signInAliases: {
    email: true,
    username: false,
  },
  standardAttributes: {
    fullname: { required: true, mutable: true },
  },
  passwordPolicy: {
    minLength: 8,
    requireDigits: true,
    requireLowercase: true,
    requireUppercase: true,
    requireSymbols: true,
  },
  selfSignUpEnabled: true,
  userVerification: {
    emailSubject: 'Verify your email !',
    emailBody: 'Thank you for signing up to our app! Your verification code is {####}',
    emailStyle: cognito.VerificationEmailStyle.CODE,
  },
  accountRecovery: cognito.AccountRecovery.EMAIL_ONLY,
  // 附加触发器
  lambdaTriggers: {
    preSignUp: validateFullnameLambda, // 注册时验证
    updateUserAttributes: validateFullnameLambda, // 更新属性时验证
  },
});

替代方案:使用自定义属性

如果业务允许使用自定义属性而非标准fullname,可直接在CDK中配置带长度限制的自定义属性:

const userPool = new cognito.UserPool(this, `name-of-user-pool-${stage}`, {
  // ...其他配置不变
  customAttributes: {
    'custom:fullname': new cognito.StringAttribute({
      minLen: 2,
      maxLen: 50,
      required: true,
      mutable: true,
    }),
  },
});

注意事项

  • Cognito标准属性fullname对应的底层字段是name,Lambda中需通过event.request.userAttributes['name']获取值。
  • 触发器抛出的错误会返回给客户端,可根据需求自定义错误信息。
  • 若仅需验证注册场景,只需添加preSignUp触发器即可;若需支持属性更新验证,需同时添加updateUserAttributes触发器。

内容的提问来源于stack exchange,提问作者Marko Pavlovic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 23:25:57