使用AWS Amplify Auth.federatedSignIn()实现社交登录遇权限错误求助
解决Cognito联邦登录报错:Token is not from a supported provider of this identity pool
问题详情
尝试通过Google社交登录完成Cognito身份认证时,触发400错误:
POST https://cognito-identity.us-east-1.amazonaws.com/ 400 ERROR NotAuthorizedException: Token is not from a supported provider of this identity pool.
已在Cognito身份池中添加Google作为身份提供商,使用的代码如下:
import { GoogleAuth } from '@codetrix-studio/capacitor-google-auth'; async googleAuth() { let googleUser = await GoogleAuth.signIn(); const token = googleUser.authentication.idToken; let user = { email: googleUser.email, name: googleUser.name, }; const expiresIn = 3600; const providerName = 'google'; try { await Auth.federatedSignIn( providerName, { token, expires_at: expiresIn * 1000 + new Date().getTime(), }, user, ); } catch (err) { console.log('ERROR', err); } }
修复方案
1. 修正提供商名称
Cognito要求Google的提供商名称为accounts.google.com,而非代码中的google,修改后代码如下:
const providerName = 'accounts.google.com';
2. 验证Google ID Token有效性
解码ID Token查看payload,确认:
iss字段值为https://accounts.google.comaud字段值与你在Google Cloud Console创建的OAuth客户端ID完全匹配
确保Token是Google合法签发且未过期。
3. 检查Cognito身份池配置
- 进入AWS控制台的Cognito身份池,确认Google提供商的客户端ID与Google Cloud中的一致
- 检查身份池的信任关系策略,确保包含Google的授权声明:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "accounts.google.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "accounts.google.com:aud": "你的Google客户端ID" } } } ] } - 确认身份池的“未验证/已验证身份”权限中已启用Google登录。
4. 修正Token过期时间计算
避免手动计算过期时间,直接使用插件返回的expiresAt值:
const { idToken, expiresAt } = googleUser.authentication; // ... await Auth.federatedSignIn( providerName, { token: idToken, expires_at: expiresAt, }, user, );
内容的提问来源于stack exchange,提问作者jewells joshi
相关产品推荐
相关产品推荐

