You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Cognito对接OIDC身份提供商时如何为authorize URL添加自定义参数

解决方案

目前有三种可落地的实现方式,按实现成本从低到高排序:

  • 方案1:初始请求携带参数透传(首选)
    你在调用Cognito /oauth2/authorize 端点(或访问托管UI入口)时,直接在请求URL中添加两个参数:
    1. identity_provider=Auth0:跳过托管UI的提供商选择步骤,直接走Auth0认证流程
    2. connection=你的Auth0连接名:Cognito会自动将该参数透传至跳转到Auth0的/authorizeURL中,部分AWS区域需要给参数加idp_前缀,即传idp_connection=你的Auth0连接名即可。
      示例请求URL:
https://<你的Cognito用户池域名>.auth.<区域>.amazoncognito.com/oauth2/authorize?client_id=<你的Cognito客户端ID>&response_type=code&scope=openid profile email&redirect_uri=<你的回调地址>&identity_provider=Auth0&connection=github
  • 方案2:CloudFormation配置硬编码参数
    如果你的connection参数是固定值,可以直接在AWS::Cognito::UserPoolIdentityProvider的ProviderDetails中手动指定带参数的授权URL,新版CloudFormation已经支持授权URL带查询参数,修改后的配置如下:
Auth0IdentityProvider:
    Type: AWS::Cognito::UserPoolIdentityProvider
    Properties:
        UserPoolId:
            Ref: CognitoUserPool
        ProviderType: "OIDC"
        ProviderName: "Auth0"
        ProviderDetails:
            client_id: "xxxx"
            client_secret: "xxxx"
            attributes_request_method: "GET"
            oidc_issuer: "https://xxxx.xx.auth0.com"
            authorize_scopes: "openid profile email"
            # 手动指定带connection参数的授权URL
            authorize_url: "https://xxxx.xx.auth0.com/authorize?connection=你的连接名"
            token_url: "https://xxxx.xx.auth0.com/oauth/token"
            attributes_url: "https://xxxx.xx.auth0.com/userinfo"
            jwks_uri: "https://xxxx.xx.auth0.com/.well-known/jwks.json"
        AttributeMapping:
            email: "email"

这里注意手动指定授权URL的同时,需要同步补充token_url、attributes_url、jwks_uri三个必填端点配置。

  • 方案3:请求重写兜底
    如果以上两种方案都不符合你的场景,可以在Cognito用户池前配置CloudFront分发,对跳转到Auth0 /authorize的请求做查询参数重写,强制添加connection参数。

内容的提问来源于stack exchange,提问作者Mattia Mari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 13:24:07