登录后刷新浏览器自动登出求助:两个Serverless项目异常排查
Hey there, let's dig into this since swapping the config.json breaks your working project, the root cause is definitely tied to that file or how your app interacts with its Cognito settings—even if you think it's correct. Here are targeted steps to troubleshoot:
Double-check Cognito core IDs for exact matches
Confirm theuserPoolIdanduserPoolWebClientIdin yourconfig.jsonare 100% identical to the ones in your AWS Console for the "Puzzling" project. It’s easy to miss a capital letter, extra space, or suffix (likeus-east-1_XXXXXX) when copying. Even a tiny mismatch will break token refresh and auth flows.Audit token storage and refresh logic
Refresh logouts usually happen because refresh tokens aren’t persisted properly. Check your frontend code:- Are you storing the
refreshTokeninlocalStorage(persists across refreshes) instead ofsessionStorage(clears on refresh)? - On page load, does your app attempt to fetch new ID/access tokens using the stored refresh token? Are you handling errors like expired tokens or invalid client configurations here?
- Pop open your browser’s DevTools > Application tab and compare token data before/after a refresh. If key tokens disappear or look malformed, that’s a red flag.
- Are you storing the
Inspect hidden Cognito app client differences
Even if yourserverless.ymllooks identical, AWS Console settings for the Cognito app client might vary:- Did you accidentally enable "Generate client secret" for the "Puzzling" client? Frontend apps don’t handle client secrets, so this will block token refresh entirely.
- Verify "Allowed OAuth Flows" includes
refresh_tokenand "Allowed OAuth Scopes" hasopenid/refresh_token—these are required for maintaining sessions across refreshes. - Check "Callback URLs" and "Sign-out URLs" to ensure they match your "Puzzling" project’s domain; mismatched URLs can trigger session invalidation on refresh.
Validate deployed Serverless resource differences
Yourserverless.ymlmight look the same, but deployed resources could have discrepancies:- Run
serverless infofor both projects and compare the Cognito resource ARNs/IDs. Ensure "Puzzling" is using the correct, newly deployed resources (not leftover old ones). - For password modification failures, check if your "Puzzling" Lambda functions have the necessary IAM permissions (like
cognito-idp:AdminUpdateUserPassword). Missing permissions will silently block these actions.
- Run
Test token validity and CORS configurations
- Use Postman or your browser’s console to call Cognito’s
InitiateAuthendpoint for "Puzzling", then try theRefreshTokenendpoint. The error message (e.g.,invalid_client,invalid_grant) will point directly to the issue. - Confirm your API Gateway CORS settings allow credentials (tokens) to be sent with requests. Cross-origin blocks on refresh can kill sessions or prevent password update requests from going through.
- Use Postman or your browser’s console to call Cognito’s
Rule out frontend caching or conditional logic
- Clear your browser’s cache (including Service Worker cache if you’re using one)—old cached configs might be overriding your new
config.json. - Check if your frontend has hardcoded logic tied to the "Working" project name (e.g., environment variable checks that don’t switch to "Puzzling"). A missed conditional could be loading incorrect auth settings.
- Clear your browser’s cache (including Service Worker cache if you’re using one)—old cached configs might be overriding your new
内容的提问来源于stack exchange,提问作者chris_st

