AWS Cognito强制MFA用户池间迁移失败问题求助
AWS Cognito强制MFA用户池迁移失败问题
问题背景
需要将原强制开启MFA的AWS Cognito用户池中的用户迁移到新的强制开启MFA的用户池,已创建UserMigration_Authentication类型的Lambda触发器,触发器可正常触发并返回以下响应:
"response": { "userAttributes": { "email": "test@example.com", "email_verified": "true", "phone_number": "+917023433333", "phone_number_verified": "true" }, "forceAliasCreation": null, "finalUserStatus": "CONFIRMED", "messageAction": "SUPPRESS", "desiredDeliveryMediums": null }
触发时的事件对象如下:
{ "version": "1", "triggerSource": "UserMigration_Authentication", "region": "us-east-1", "userPoolId": "us-east-1_newPoold", "userName": "test@example.com", "callerContext": { "awsSdkVersion": "aws-sdk-unknown-unknown", "clientId": "dddaio06kd1ls20sss5cpgddd" }, "request": { "password": "Test@123", "validationData": {}, "userAttributes": null }, "response": { "userAttributes": null, "forceAliasCreation": null, "finalUserStatus": null, "messageAction": null, "desiredDeliveryMediums": null } }
当前现状:将用户迁移到非强制MFA的用户池时,脚本可正常工作,用户成功创建;但迁移到强制MFA的用户池时流程失败,使用的Lambda代码基于Collaborne的Cognito用户池迁移实现。
问题原因与解决办法
核心原因
目标用户池强制开启MFA时,迁移流程需要满足额外的MFA验证要求:
- 用户必须拥有已验证的联系方式(邮箱或手机号,对应属性
email_verified/phone_number_verified为true) - 迁移后的用户需要启用MFA状态,且默认迁移逻辑未处理强制MFA场景下的用户状态同步
具体修复步骤
补充MFA相关用户属性
在Lambda返回的userAttributes中添加mfa_enabled属性并设置为true,明确启用用户的MFA状态:"userAttributes": { "email": "test@example.com", "email_verified": "true", "phone_number": "+917023433333", "phone_number_verified": "true", "mfa_enabled": "true" }同步原用户的MFA配置
在Lambda逻辑中添加步骤:- 调用原用户池的
AdminGetUser接口,获取用户的UserMFASettingList属性(记录原用户启用的MFA类型,如TOTP、短信) - 迁移完成后,调用目标用户池的
AdminSetUserMFAPreference接口,将原用户的MFA设置同步到新用户
- 调用原用户池的
调整用户最终状态
如果原用户未完成MFA验证(或无法同步MFA设备),不要将finalUserStatus设为CONFIRMED,改为RESET_REQUIRED,引导用户首次登录时完成MFA设置:"finalUserStatus": "RESET_REQUIRED"检查用户池客户端配置
确保目标用户池的客户端配置与强制MFA要求匹配:- 启用客户端的MFA强制选项
- 确保客户端支持的OAuth流程兼容MFA验证
修改后的Lambda响应示例
{ "response": { "userAttributes": { "email": "test@example.com", "email_verified": "true", "phone_number": "+917023433333", "phone_number_verified": "true", "mfa_enabled": "true" }, "forceAliasCreation": null, "finalUserStatus": "CONFIRMED", "messageAction": "SUPPRESS", "desiredDeliveryMediums": ["SMS"] } }
内容的提问来源于stack exchange,提问作者Sagar Kharche
相关产品推荐
相关产品推荐

