You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Cognito对接Google登录后,如何将注册信息存入用户池?

我明白你现在的处境——已经把Google登录和AWS Cognito身份池对接成功了,但想把用户的注册信息(还有自定义属性)存到Cognito用户池里,却摸不着头绪对吧?别慌,咱们一步步来搞定这个问题。

解决方案:将Google登录用户信息同步到AWS Cognito用户池并添加自定义属性

你当前的代码只完成了**Cognito身份池(Identity Pool)**的身份验证,拿到了AWS临时凭证,但用户池(User Pool)是独立的用户管理系统,需要额外调用API来创建/更新用户并存储信息。下面是具体实现步骤:

1. 前期准备:配置用户池与Google身份提供商

  • 先在Cognito用户池后台开启Google作为身份提供商,配置好Google的客户端ID、密钥,确保回调URL与Google开发者平台的设置一致。
  • 在用户池的属性页面添加你需要的自定义属性(比如custom:userRole、custom:favoriteCategory),注意自定义属性必须以custom:开头。

2. 修改前端代码:获取Google用户信息并写入用户池

你需要先从Google接口拿到用户的基础信息,再通过Cognito SDK将信息(含自定义属性)存入用户池。这里以原生Cognito JavaScript SDK为例:

首先引入必要的SDK(如果还没添加):

<script src="https://sdk.amazonaws.com/js/aws-sdk-2.1000.0.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/amazon-cognito-identity-js@5.2.9/dist/amazon-cognito-identity-js.min.js"></script>

然后修改你的signinCallback函数,加入用户池操作逻辑:

function signinCallback(authResult) {
    AWS.config.region = 'us-XXXXXXX-1';
    
    // 1. 先获取Google用户的完整信息
    gapi.client.load('oauth2', 'v2', function() {
        gapi.client.oauth2.userinfo.get().execute(function(googleUser) {
            console.log("Google用户信息:", googleUser);
            
            // 2. 配置Cognito用户池参数
            const userPoolId = 'us-XXXXXXX-1_XXXXXXXXX'; // 替换为你的用户池ID
            const clientId = 'XXXXXXXXXXXXXXXXXXXXXXXXXXXX'; // 替换为用户池的App客户端ID
            const userPool = new AmazonCognitoIdentity.CognitoUserPool({
                UserPoolId: userPoolId,
                ClientId: clientId
            });
            
            // 3. 准备要存储的用户属性(含自定义属性)
            const attributeList = [];
            // 系统默认属性
            attributeList.push(new AmazonCognitoIdentity.CognitoUserAttribute({
                Name: 'name',
                Value: googleUser.name
            }));
            attributeList.push(new AmazonCognitoIdentity.CognitoUserAttribute({
                Name: 'email',
                Value: googleUser.email
            }));
            // 自定义属性示例
            attributeList.push(new AmazonCognitoIdentity.CognitoUserAttribute({
                Name: 'custom:userRole',
                Value: 'customer' // 可根据业务逻辑动态设置
            }));
            
            // 4. 关联Google用户与Cognito用户池,自动创建或更新用户
            const cognitoClient = new AWS.CognitoIdentityServiceProvider();
            const linkParams = {
                ProviderName: 'Google',
                ProviderAttributeName: 'Cognito_Subject',
                ProviderAttributeValue: authResult.id_token,
                UserPoolId: userPoolId,
                ClientId: clientId,
                UserAttributes: attributeList
            };
            
            cognitoClient.adminLinkProviderForUser(linkParams, function(err, data) {
                if (err) {
                    // 如果用户已存在,会抛出ResourceConflictException,此时更新属性
                    if (err.code === 'ResourceConflictException') {
                        // 通过邮箱查询用户ID
                        const getUserParams = {
                            UserPoolId: userPoolId,
                            Filter: `email = "${googleUser.email}"`,
                            Limit: 1
                        };
                        cognitoClient.listUsers(getUserParams, function(getErr, getRes) {
                            if (!getErr && getRes.Users.length > 0) {
                                const updateParams = {
                                    UserPoolId: userPoolId,
                                    Username: getRes.Users[0].Username,
                                    UserAttributes: attributeList
                                };
                                cognitoClient.adminUpdateUserAttributes(updateParams, function(updateErr) {
                                    updateErr ? console.error("更新属性失败:", updateErr) : console.log("用户属性更新成功");
                                });
                            }
                        });
                    } else {
                        console.error("关联用户失败:", err);
                    }
                } else {
                    console.log("用户创建并关联成功:", data);
                }
            });
            
            // 保留原有的身份池凭证逻辑
            AWS.config.credentials = new AWS.CognitoIdentityCredentials({
                IdentityPoolId: 'us-XXXX-1:XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX',
                RoleArn: 'arn:aws:iam::XXXXXXXX:role/Cognito_XXXXXXXXXUnauth_Role',
                Logins: {
                    'accounts.google.com': authResult['id_token']
                }
            });
            
            AWS.config.credentials.get(function (err) {
                err ? console.log(err) : (
                    console.log(AWS.config.credentials),
                    console.log("Cognito Identity Id: " + AWS.config.credentials.identityId)
                );
            });
        });
    });
}

3. 关键注意事项

  • 权限配置:确保你使用的IAM角色(Cognito_XXXXXXXXXUnauth_Role)拥有cognito-idp:AdminLinkProviderForUser、cognito-idp:ListUsers、cognito-idp:AdminUpdateUserAttributes这几个API的调用权限,否则会出现权限不足的错误。
  • 用户存在判断:adminLinkProviderForUser会自动创建新用户,但如果用户已存在会抛出异常,这时我们需要通过listUsers查询用户ID,再调用adminUpdateUserAttributes更新属性。
  • Google信息获取:通过gapi.client.oauth2.userinfo.get()可以拿到用户的姓名、邮箱、唯一标识sub等信息,这些都可以作为属性存入用户池。

4. 简化方案:使用AWS Amplify

如果觉得原生SDK太繁琐,推荐用AWS Amplify来简化流程,它已经封装了Google登录和用户池同步的逻辑:

// 配置Amplify
Amplify.configure({
    Auth: {
        region: 'us-XXXXXXX-1',
        userPoolId: 'us-XXXXXXX-1_XXXXXXXXX',
        userPoolWebClientId: 'XXXXXXXXXXXXXXXXXXXXXXXXXXXX',
        oauth: {
            domain: 'your-user-pool-domain.auth.us-XXXXXXX-1.amazoncognito.com',
            scope: ['email', 'openid', 'profile'],
            redirectSignIn: 'https://your-domain.com/callback',
            redirectSignOut: 'https://your-domain.com/signout',
            responseType: 'code'
        }
    }
});

// 登录后自动同步用户信息到用户池,并更新自定义属性
Auth.federatedSignIn({provider: 'Google'}).then(user => {
    console.log("用户信息已同步到用户池:", user);
    Auth.updateUserAttributes(user, {
        'custom:userRole': 'customer'
    }).then(() => console.log("自定义属性更新成功"));
});

这样就能轻松实现把Google登录用户的信息(含自定义属性)存入Cognito用户池了。

内容的提问来源于stack exchange,提问作者mugzi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:55:32