Amazon Cognito对接OIDC身份提供商时如何为authorize URL添加自定义参数
解决方案
目前有三种可落地的实现方式,按实现成本从低到高排序:
- 方案1:初始请求携带参数透传(首选)
你在调用Cognito/oauth2/authorize端点(或访问托管UI入口)时,直接在请求URL中添加两个参数:identity_provider=Auth0:跳过托管UI的提供商选择步骤,直接走Auth0认证流程connection=你的Auth0连接名:Cognito会自动将该参数透传至跳转到Auth0的/authorizeURL中,部分AWS区域需要给参数加idp_前缀,即传idp_connection=你的Auth0连接名即可。
示例请求URL:
https://<你的Cognito用户池域名>.auth.<区域>.amazoncognito.com/oauth2/authorize?client_id=<你的Cognito客户端ID>&response_type=code&scope=openid profile email&redirect_uri=<你的回调地址>&identity_provider=Auth0&connection=github
- 方案2:CloudFormation配置硬编码参数
如果你的connection参数是固定值,可以直接在AWS::Cognito::UserPoolIdentityProvider的ProviderDetails中手动指定带参数的授权URL,新版CloudFormation已经支持授权URL带查询参数,修改后的配置如下:
Auth0IdentityProvider: Type: AWS::Cognito::UserPoolIdentityProvider Properties: UserPoolId: Ref: CognitoUserPool ProviderType: "OIDC" ProviderName: "Auth0" ProviderDetails: client_id: "xxxx" client_secret: "xxxx" attributes_request_method: "GET" oidc_issuer: "https://xxxx.xx.auth0.com" authorize_scopes: "openid profile email" # 手动指定带connection参数的授权URL authorize_url: "https://xxxx.xx.auth0.com/authorize?connection=你的连接名" token_url: "https://xxxx.xx.auth0.com/oauth/token" attributes_url: "https://xxxx.xx.auth0.com/userinfo" jwks_uri: "https://xxxx.xx.auth0.com/.well-known/jwks.json" AttributeMapping: email: "email"
这里注意手动指定授权URL的同时,需要同步补充token_url、attributes_url、jwks_uri三个必填端点配置。
- 方案3:请求重写兜底
如果以上两种方案都不符合你的场景,可以在Cognito用户池前配置CloudFront分发,对跳转到Auth0/authorize的请求做查询参数重写,强制添加connection参数。
内容的提问来源于stack exchange,提问作者Mattia Mari
相关产品推荐
相关产品推荐

