如何用Terraform配置AWS Cognito用户池启用邮箱登录而非用户名?
如何用Terraform配置AWS Cognito用户池仅用邮箱登录
我尝试用Terraform创建AWS Cognito用户池,想要设置为「电子邮件地址或电话号码」→「允许使用电子邮件地址」(对应截图中红色标注项),但目前默认选中的是「用户名」→「同时允许使用已验证的电子邮件地址」。我希望用户池不使用用户名,仅用邮箱登录,但无论怎么调整现有配置,都无法实现。
现有main.tf相关代码:
resource "aws_cognito_user_pool" "app_cognito_user_pool" { name = "app_cognito_user_pool" alias_attributes = ["email"] auto_verified_attributes = ["email"] account_recovery_setting { recovery_mechanism { name = "verified_email" priority = 1 } } } resource "aws_cognito_user_pool_client" "app_cognito_user_pool_client" { name = "app_cognito_user_pool_client" user_pool_id = aws_cognito_user_pool.app_cognito_user_pool.id prevent_user_existence_errors = "ENABLED" supported_identity_providers = ["COGNITO"] } resource "aws_cognito_user_pool_domain" "app_cognito_user_pool_domain" { domain = "app" user_pool_id = aws_cognito_user_pool.app_cognito_user_pool.id }
要实现仅用邮箱登录,需要在aws_cognito_user_pool资源中添加两个关键配置:
username_attributes:指定用户登录时的唯一标识符为邮箱,替换默认的用户名- 自定义
schema:禁用默认的必填用户名属性
修改后的aws_cognito_user_pool资源代码如下:
resource "aws_cognito_user_pool" "app_cognito_user_pool" { name = "app_cognito_user_pool" alias_attributes = ["email"] auto_verified_attributes = ["email"] # 指定邮箱作为登录标识,对应控制台的「电子邮件地址或电话号码」选项 username_attributes = ["email"] account_recovery_setting { recovery_mechanism { name = "verified_email" priority = 1 } } # 覆盖默认规则,设置用户名非必填 schema { name = "username" attribute_data_type = "String" mutable = false required = false } }
配置说明:
username_attributes = ["email"]:直接将邮箱设为用户的登录凭证,替代默认的用户名逻辑- 自定义
schema中的username属性并设置required = false:取消Cognito默认强制要求用户名的规则,确保用户仅需邮箱即可完成注册和登录
内容的提问来源于stack exchange,提问作者pragMATHiC
相关产品推荐
相关产品推荐

