启用PreventUserExistenceErrors时,Go语言Cognito迁移Lambda如何返回空响应?
I’ve run into this exact issue before with Cognito’s user migration triggers and PreventUserExistenceErrors—the key misunderstanding here is what Cognito actually considers an "empty response". Returning nil, an empty string, or an anonymous empty struct won’t work because Lambda serializes those values to null or invalid JSON, which Cognito interprets as a trigger execution failure instead of a signal that the user doesn’t exist.
The Fix: Return a Valid Empty JSON Object
Cognito expects a properly formatted JSON response (even if it’s empty) to recognize that you’ve intentionally indicated the user doesn’t exist. In Go, you can do this in two reliable ways:
Option 1: Use a Typed Struct with omitempty Tags
Define a struct that matches the Cognito user migration response schema, with all fields marked as optional via omitempty. Returning an instance of this empty struct will serialize to {}, which Cognito interprets correctly.
package main import ( "fmt" "github.com/aws/aws-lambda-go/lambda" ) // MigrationResponse matches the expected Cognito user migration response structure type MigrationResponse struct { UserAttributes map[string]string `json:"userAttributes,omitempty"` Username string `json:"username,omitempty"` ForceAliasCreation bool `json:"forceAliasCreation,omitempty"` } func Handle(event interface{}) (interface{}, error) { fmt.Println("User not found, returning empty migration response") // Return an empty struct - omitempty tags ensure no fields are serialized return MigrationResponse{}, nil } func main() { lambda.Start(Handle) }
Option 2: Return an Empty Map
If you don’t want to define a struct, returning an empty map[string]interface{} will also serialize to {}, which works just as well:
package main import ( "fmt" "github.com/aws/aws-lambda-go/lambda" ) func Handle(event interface{}) (interface{}, error) { fmt.Println("User not found, returning empty response map") return map[string]interface{}{}, nil } func main() { lambda.Start(Handle) }
Why This Works
When you return either of these, Lambda serializes the response to a valid empty JSON object ({}). Cognito recognizes this as your signal that the user doesn’t exist in the legacy system, and then honors the PreventUserExistenceErrors setting by returning the generic NotAuthorizedException ("Incorrect username or password") instead of exposing that the user isn’t found.
What Was Wrong Before
Returning nil from your handler makes Lambda serialize the response to null, which Cognito treats as an unexpected failure in the trigger execution—hence the UserNotFoundException about the migration failing. Empty strings or anonymous structs have similar issues with serialization that don’t match what Cognito expects for an intentional "user not found" response.
After deploying this fix, test with your client again—you should get the same generic error as you did when no migration trigger was configured.
内容的提问来源于stack exchange,提问作者Mic Jaw

