You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过AWS Cognito与DynamoDB实现特定用户层级权限管控?

AWS Cognito + DynamoDB 权限方案实现(Group A专属需求)

需求1:创建新用户仅能加入Group B

实现步骤:

  • IAM策略限制:给Group A附加以下IAM策略,仅允许创建用户并将其添加至Group B:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "cognito-idp:AdminCreateUser",
      "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID"
    },
    {
      "Effect": "Allow",
      "Action": "cognito-idp:AdminAddUserToGroup",
      "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID/group/GroupB"
    }
  ]
}
  • Lambda自动分组:配置Cognito的Post Confirmation触发Lambda,新用户注册完成后自动加入Group B:
import boto3

cognito = boto3.client('cognito-idp')

def lambda_handler(event, context):
    user_pool_id = event['userPoolId']
    username = event['userName']
    
    cognito.admin_add_user_to_group(
        UserPoolId=user_pool_id,
        Username=username,
        GroupName='GroupB'
    )
    return event

需求2:查看并更新自身数据(所有者权限范围)

实现步骤:

  • DynamoDB表设计:将用户Cognito身份ID(sub)设为主键(命名为ownerSub)。
  • IAM策略配置:给Group A附加以下DynamoDB权限策略,限制仅能操作自身数据:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "dynamodb:GetItem",
        "dynamodb:PutItem",
        "dynamodb:UpdateItem"
      ],
      "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/YOUR_TABLE_NAME",
      "Condition": {
        "StringEquals": {
          "dynamodb:LeadingKeys": "${cognito-identity.amazonaws.com:sub}"
        }
      }
    }
  ]
}

需求3:仅查看并更新自身创建的Group B用户

实现步骤:

  • 用户属性扩展:在Cognito用户池中添加自定义属性custom:createdBy,存储创建该用户的Group A用户sub。
  • 创建用户时写入属性:修改创建用户的逻辑,将当前Group A用户的sub写入新用户的custom:createdBy属性,可通过Lambda自动完成:
# 扩展需求1的Lambda逻辑
def lambda_handler(event, context):
    creator_sub = event['request']['userAttributes']['sub']
    user_pool_id = event['userPoolId']
    username = event['userName']
    
    # 写入创建者标识
    cognito.admin_update_user_attributes(
        UserPoolId=user_pool_id,
        Username=username,
        UserAttributes=[
            {
                'Name': 'custom:createdBy',
                'Value': creator_sub
            }
        ]
    )
    # 加入Group B
    cognito.admin_add_user_to_group(
        UserPoolId=user_pool_id,
        Username=username,
        GroupName='GroupB'
    )
    return event
  • IAM策略限制:给Group A附加Cognito权限策略,仅允许操作custom:createdBy等于自身sub的用户:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cognito-idp:AdminGetUser",
        "cognito-idp:AdminUpdateUserAttributes"
      ],
      "Resource": "arn:aws:cognito-idp:REGION:ACCOUNT_ID:userpool/USER_POOL_ID",
      "Condition": {
        "StringEquals": {
          "cognito-idp:userAttributes/custom:createdBy": "${cognito-identity.amazonaws.com:sub}"
        }
      }
    }
  ]
}

需求4:授权指定Group B用户查看特定数据

实现步骤:

  • DynamoDB表结构扩展:在数据表中添加authorizedUsers数组字段,存储被授权用户的sub列表。
  • IAM策略配置:修改DynamoDB权限策略,允许用户访问数据的条件为「自身是所有者」或「自身sub在authorizedUsers数组中」;同时允许Group A用户更新该字段:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "dynamodb:GetItem",
      "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/YOUR_TABLE_NAME",
      "Condition": {
        "Or": [
          {
            "StringEquals": {
              "dynamodb:LeadingKeys": "${cognito-identity.amazonaws.com:sub}"
            }
          },
          {
            "Contains": {
              "dynamodb:Item/authorizedUsers": "${cognito-identity.amazonaws.com:sub}"
            }
          }
        ]
      }
    },
    {
      "Effect": "Allow",
      "Action": "dynamodb:UpdateItem",
      "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/YOUR_TABLE_NAME",
      "Condition": {
        "StringEquals": {
          "dynamodb:LeadingKeys": "${cognito-identity.amazonaws.com:sub}"
        },
        "ForAllValues:StringEquals": {
          "dynamodb:Attributes": ["authorizedUsers"]
        }
      }
    }
  ]
}
  • 业务逻辑实现:Group A用户通过API或后台操作更新目标数据的authorizedUsers数组,添加指定Group B用户的sub即可完成授权。

内容的提问来源于stack exchange,提问作者ViniciusCR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 22:15:52