You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Timestream访问被拒:已授权角色仍无法执行DescribeEndpoints

解决Cognito未授权角色访问Timestream DescribeEndpoints的403权限问题

核心问题分析

错误提示明确指出会话策略(Session Policy)未允许timestream:DescribeEndpoints动作——即使角色本身已附加对应权限,Cognito身份池的会话策略会对临时凭证施加额外限制,这是导致权限拦截的核心原因。

解决步骤

1. 检查Cognito身份池的会话策略

  • 进入AWS Cognito控制台,找到目标身份池
  • 切换到「身份池设置」>「未授权身份的访问角色」,点击「编辑」
  • 若存在附加的会话策略文档,必须添加timestream:DescribeEndpoints的允许权限,示例如下:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": "timestream:DescribeEndpoints",
          "Resource": "*"
        },
        {
          "Effect": "Allow",
          "Action": "timestream:Query",
          "Resource": "arn:aws:timestream:us-west-2:<你的账号ID>:database/solarpanel_test/table/solarpanel_test"
        }
      ]
    }
    
  • 若无会话策略,直接进入下一步验证。

2. 复用凭证提供者避免重复初始化

代码中两次独立调用fromCognitoIdentityPool创建凭证实例,可能导致会话策略应用不一致。修改为复用同一个凭证对象:

import * as AWS from "@aws-sdk/client-timestream-query";
import { CognitoIdentityClient } from "@aws-sdk/client-cognito-identity";
import { fromCognitoIdentityPool } from "@aws-sdk/credential-provider-cognito-identity";
import { useEffect } from 'react';
import logo from './logo.svg';

function App() {

  useEffect(() => {
    (async () => {
      // 复用同一个凭证提供者
      const credentials = fromCognitoIdentityPool({
        client: new CognitoIdentityClient({ region: "us-west-2" }),
        identityPoolId: "<IDENTITY_POOL_ID>",
      });

      const endpointsQueryClient = new AWS.TimestreamQuery({ 
        region: "us-west-2",
        credentials
      });
      const qClientResponse = await endpointsQueryClient.describeEndpoints({});
      console.log(qClientResponse);

      const queryClient = new AWS.TimestreamQuery({
        region: "us-west-2",
        credentials,
        endpoint: `https://${qClientResponse.Endpoints[0].Address}`,
      });

      const QueryString = `SELECT * FROM solarpanel_test.solarpanel_test WHERE time between ago(30000m) and now() ORDER BY time DESC LIMIT 200`;
      console.log(await queryClient.query({ QueryString }));

    })()
  }, [])

  return (
    <div className="App">
      <header className="App-header">
        <img src={logo} className="App-logo" alt="logo" />
        <p>
          Edit <code>src/App.js</code> and save to reload.
        </p>
        <a
          className="App-link"
          href="https://reactjs.org"
          target="_blank"
          rel="noopener noreferrer"
        >
          Learn React
        </a>
      </header>
    </div>
  );
}

export default App;

3. 验证IAM角色策略与信任关系

  • 确认Cognito_izunumaUnauth_Role附加的策略包含必要权限:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "timestream:DescribeEndpoints",
            "timestream:Query"
          ],
          "Resource": "*"
        }
      ]
    }
    
  • 检查角色的信任关系,确保Cognito可以扮演该角色:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "cognito-identity.amazonaws.com"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "cognito-identity.amazonaws.com:aud": "<你的身份池ID>"
            },
            "ForAnyValue:StringLike": {
              "cognito-identity.amazonaws.com:amr": "unauthenticated"
            }
          }
        }
      ]
    }
    

4. 清除浏览器缓存测试

浏览器可能缓存了旧的临时凭证,导致新策略未生效。使用无痕模式打开应用,或清除浏览器缓存与本地存储后重试。


内容的提问来源于stack exchange,提问作者hiro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 18:25:34