AWS Timestream访问被拒:已授权角色仍无法执行DescribeEndpoints
解决Cognito未授权角色访问Timestream DescribeEndpoints的403权限问题
核心问题分析
错误提示明确指出会话策略(Session Policy)未允许timestream:DescribeEndpoints动作——即使角色本身已附加对应权限,Cognito身份池的会话策略会对临时凭证施加额外限制,这是导致权限拦截的核心原因。
解决步骤
1. 检查Cognito身份池的会话策略
- 进入AWS Cognito控制台,找到目标身份池
- 切换到「身份池设置」>「未授权身份的访问角色」,点击「编辑」
- 若存在附加的会话策略文档,必须添加
timestream:DescribeEndpoints的允许权限,示例如下:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "timestream:DescribeEndpoints", "Resource": "*" }, { "Effect": "Allow", "Action": "timestream:Query", "Resource": "arn:aws:timestream:us-west-2:<你的账号ID>:database/solarpanel_test/table/solarpanel_test" } ] } - 若无会话策略,直接进入下一步验证。
2. 复用凭证提供者避免重复初始化
代码中两次独立调用fromCognitoIdentityPool创建凭证实例,可能导致会话策略应用不一致。修改为复用同一个凭证对象:
import * as AWS from "@aws-sdk/client-timestream-query"; import { CognitoIdentityClient } from "@aws-sdk/client-cognito-identity"; import { fromCognitoIdentityPool } from "@aws-sdk/credential-provider-cognito-identity"; import { useEffect } from 'react'; import logo from './logo.svg'; function App() { useEffect(() => { (async () => { // 复用同一个凭证提供者 const credentials = fromCognitoIdentityPool({ client: new CognitoIdentityClient({ region: "us-west-2" }), identityPoolId: "<IDENTITY_POOL_ID>", }); const endpointsQueryClient = new AWS.TimestreamQuery({ region: "us-west-2", credentials }); const qClientResponse = await endpointsQueryClient.describeEndpoints({}); console.log(qClientResponse); const queryClient = new AWS.TimestreamQuery({ region: "us-west-2", credentials, endpoint: `https://${qClientResponse.Endpoints[0].Address}`, }); const QueryString = `SELECT * FROM solarpanel_test.solarpanel_test WHERE time between ago(30000m) and now() ORDER BY time DESC LIMIT 200`; console.log(await queryClient.query({ QueryString })); })() }, []) return ( <div className="App"> <header className="App-header"> <img src={logo} className="App-logo" alt="logo" /> <p> Edit <code>src/App.js</code> and save to reload. </p> <a className="App-link" href="https://reactjs.org" target="_blank" rel="noopener noreferrer" > Learn React </a> </header> </div> ); } export default App;
3. 验证IAM角色策略与信任关系
- 确认
Cognito_izunumaUnauth_Role附加的策略包含必要权限:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "timestream:DescribeEndpoints", "timestream:Query" ], "Resource": "*" } ] } - 检查角色的信任关系,确保Cognito可以扮演该角色:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "cognito-identity.amazonaws.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "cognito-identity.amazonaws.com:aud": "<你的身份池ID>" }, "ForAnyValue:StringLike": { "cognito-identity.amazonaws.com:amr": "unauthenticated" } } } ] }
4. 清除浏览器缓存测试
浏览器可能缓存了旧的临时凭证,导致新策略未生效。使用无痕模式打开应用,或清除浏览器缓存与本地存储后重试。
内容的提问来源于stack exchange,提问作者hiro
相关产品推荐
相关产品推荐

