You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新邮箱verifyAttribute验证报User is not authenticated错误

问题

执行邮箱更新操作后,提交发送至用户邮箱的验证码,调用verifyAttribute方法完成验证时,系统抛出错误:User is not authenticated。
单独调用getUser方法可正常返回CognitoUser实例,相关代码如下:

onSubmitEmailConfirmation = async (values) => {
    const { code, newEmail, password } = this.state;
    const { first_name, last_name, email } = this.props.data;
      getSession()
        .then(({ user, email }) => {
          authenticate(email, password).then(() => {
            getUser(email).verifyAttribute("email", code, {
              onSuccess: () => {
                this.props.updateUserData({
                  email: newEmail,
                  first_name: first_name,
                  last_name: last_name
                });
                this.updateNotificationMessages(
                  "Email verified with success!",
                  newEmail
                );
                this.openNotificationWithIcon("success");
              },
              onFailure: (err) => {
                this.updateNotificationMessages(
                  "There was a error confirming your email",
                  err.message
                );
                this.openNotificationWithIcon("error");
              }
            });
          });
        })
        .catch((err) => {
          this.updateNotificationMessages(
          "There was a error confirming your email",
          err.message
        );
          this.openNotificationWithIcon("error");
        });
  };
错误原因
  1. 核心问题:verifyAttribute属于需要用户认证态才能调用的接口,只会读取CognitoUser实例上挂载的有效会话凭证。你通过getUser(email)拿到的是全新初始化的实例,没有绑定authenticate认证成功后下发的token,自然会返回未认证错误。
  2. 代码额外隐患:Promise链式调用没有做返回值传递,authenticate内部的报错不会被外层catch捕获,容易出现静默失败;getSession已经返回了带有效会话的user实例,完全没有复用,反而额外调用getUser生成新实例,属于多余操作。
修复方案

直接复用authenticate认证成功后返回的、已挂载有效凭证的CognitoUser实例调用verifyAttribute,同时调整Promise链保证所有错误都能被统一捕获,修复后代码如下:

onSubmitEmailConfirmation = async (values) => {
  const { code, newEmail, password } = this.state;
  const { first_name, last_name } = this.props.data;
  getSession()
    .then(({ email: sessionEmail }) => {
      // 认证后返回带有效会话的用户实例
      return authenticate(sessionEmail, password);
    })
    .then((cognitoUser) => {
      // 直接用带认证凭证的实例调用验证接口,无需重新getUser
      cognitoUser.verifyAttribute("email", code, {
        onSuccess: () => {
          this.props.updateUserData({
            email: newEmail,
            first_name: first_name,
            last_name: last_name
          });
          this.updateNotificationMessages(
            "Email verified with success!",
            newEmail
          );
          this.openNotificationWithIcon("success");
        },
        onFailure: (err) => {
          this.updateNotificationMessages(
            "There was a error confirming your email",
            err.message
          );
          this.openNotificationWithIcon("error");
        }
      });
    })
    .catch((err) => {
      this.updateNotificationMessages(
        "There was a error confirming your email",
        err.message
      );
      this.openNotificationWithIcon("error");
    });
};

补充说明:这里取会话中的邮箱做认证,而不是直接用props里的email,是为了避免props数据和当前实际登录态不同步导致的认证失败问题。

内容的提问来源于stack exchange,提问作者Lucas Fernandes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.01 20:03:39