测试网站使用AWS Elastic Transcoder遇403权限拒绝异常求助
Hey there, let's break down this 403 error you're hitting with AWS Elastic Transcoder and Cognito. The error message is pretty explicit, so let's walk through the most likely fixes step by step:
Cognito_Unauth_Role The core issue here is that your unauthenticated Cognito role doesn't have permission to run elastictranscoder:CreateJob on your specific pipeline. Let's verify the policy attached to Cognito_Unauth_Role:
Your policy needs to explicitly allow the elastictranscoder:CreateJob action for your pipeline's ARN. It should look something like this (replace placeholders with your actual values):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "elastictranscoder:CreateJob", "Resource": "arn:aws:elastictranscoder:us-east-1:YOUR_ACCOUNT_ID:pipeline/YOUR_PIPELINE_ID" } ] }
- Make sure there are no typos in the ARN—even a single incorrect character will trigger a 403.
- If you need broader access (not recommended for production), you can use a wildcard like
arn:aws:elastictranscoder:us-east-1:YOUR_ACCOUNT_ID:pipeline/*, but stick to the specific pipeline if possible.
Sometimes the policy is right, but the identity pool isn't properly connected to the role. Here's how to check:
- Go to your Cognito Identity Pool settings in the AWS Console
- Navigate to the Identity providers tab
- Under Unauthenticated identities, ensure the selected role is
Cognito_Unauth_Role - If you're using authenticated users, repeat this check for the Authenticated identities section
Looking at your code sample, I spotted curly quotes (‘/“ instead of straight '/")—these can break parameter parsing. Replace them with standard quotes, and double-check your parameter values:
AWS.config.region = 'us-east-1'; AWS.config.credentials = new AWS.CognitoIdentityCredentials({ IdentityPoolId: "us-east-1:xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx", }); var elastictranscoder = new AWS.ElasticTranscoder(); var button = document.getElementById('button'); button.addEventListener('click', function() { var params = { PipelineId: 'your-pipeline-id', /* required */ Input: { Key: "your-input-file-key" }, OutputKeyPrefix: 'your-output-prefix/', Outputs: [{ Key: 'output-file.mp4', PresetId: 'your-preset-id', }], }; elastictranscoder.createJob(params, function(err, data) { if (err) console.log(err, err.stack); else console.log(data); }); });
Also, ensure the PipelineId matches exactly with the ID in your pipeline ARN, and the Input.Key has no invalid spaces or slashes.
- Permission Boundaries: If your
Cognito_Unauth_Rolehas a permission boundary attached, it might be overriding your policy. Go to the role's IAM page, check the Permissions boundary section, and confirm it allowselastictranscoder:CreateJob. - Trust Policy: Verify the role's trust policy allows Cognito to assume it. It should include this statement:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "cognito-identity.amazonaws.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "cognito-identity.amazonaws.com:aud": "YOUR_IDENTITY_POOL_ID" }, "ForAnyValue:StringLike": { "cognito-identity.amazonaws.com:amr": "unauthenticated" } } } ] }
If you're still stuck, try using the AWS CLI to assume the Cognito_Unauth_Role and run CreateJob manually. This will tell you if the problem is in your code or the IAM configuration:
# Assume the role aws sts assume-role --role-arn "arn:aws:iam::YOUR_ACCOUNT_ID:role/Cognito_Unauth_Role" --role-session-name "test-transcoder" # Use the returned AccessKeyId, SecretAccessKey, and SessionToken to run CreateJob aws elastictranscoder create-job --pipeline-id YOUR_PIPELINE_ID --input Key=YOUR_INPUT_KEY --outputs Key=OUTPUT_KEY PresetId=YOUR_PRESET_ID --region us-east-1
Start with the IAM policy check first—it's the most common cause of this exact error. Once that's sorted, the other checks should wrap up any remaining issues.
内容的提问来源于stack exchange,提问作者Carel Fourie

