You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS SDK刷新用户令牌时遇错误,附自定义实现代码

Troubleshooting AWS Cognito Refresh Token Errors in Your Strapi Function

Let’s walk through the most common issues that could be causing your refresh token error, plus targeted fixes for your code:

1. Fix Parameter Issues (Including a Critical Typo)

Looking at your params object, there are two easy fixes to start with:

  • Typo Alert: AWSUserPollId should be AWSUserPoolId (you wrote "Poll" instead of "Pool"!). This is a frequent culprit for "resource not found" errors.
  • Trailing Comma: The comma after REFRESH_TOKEN: refreshToken in AuthParameters can cause syntax errors in older JavaScript environments—remove it.

Here’s the corrected params block:

const params = { 
  AuthFlow: 'REFRESH_TOKEN_AUTH', 
  ClientId: strapi.config.AWSClientAppId, 
  UserPoolId: strapi.config.AWSUserPoolId, // Fixed the typo here
  AuthParameters: { 
    REFRESH_TOKEN: refreshToken
    // Add USERNAME: 'user-actual-username' here if your user pool requires it for token refresh
  } 
};

Note: Some user pool setups require the USERNAME parameter alongside the refresh token for REFRESH_TOKEN_AUTH—if you get a "missing parameter" error, add that line.

2. Verify IAM Permissions

The IAM role or credentials your Strapi server uses needs explicit permission to call cognito-idp:AdminInitiateAuth. Make sure your IAM policy includes this:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "cognito-idp:AdminInitiateAuth",
      "Resource": "arn:aws:cognito-idp:YOUR_REGION:YOUR_ACCOUNT_ID:userpool/YOUR_USER_POOL_ID"
    }
  ]
}

Double-check that the credentials your app is using (environment variables, IAM role for EC2/EKS, etc.) have this policy attached.

3. Validate the Refresh Token Itself

Even with perfect code, a bad token will fail:

  • Expired Token: Cognito refresh tokens expire after 30 days by default (you can adjust this in your user pool’s App client settings).
  • Revoked Token: If the user changed their password, signed out globally, or their account was disabled, the refresh token becomes invalid.
  • Wrong Client ID: The ClientId in your params must match the one that originally issued the refresh token (each app client in your user pool has its own tokens).

4. Update Your AWS SDK

Older versions of the AWS SDK for JavaScript (v2) can have bugs or outdated requirements for adminInitiateAuth. Run this to update to the latest v2 version:

npm update aws-sdk

If you’re considering migrating to v3 later, keep in mind the syntax changes drastically—but your current code is v2-compatible, so updating is the quick fix here.

5. Improve Error Logging to Get Specific Details

Your current error handling only rejects the error, but AWS errors include detailed messages that tell you exactly what’s wrong. Add a console log to capture the full error object:

return new Promise(function (resolve, reject) { 
  provider.adminInitiateAuth(params, function (err, session) { 
    if (err) { 
      console.error('Cognito Refresh Error Details:', err); // Log the full error
      return reject(err); 
    } 
    resolve(session);
  });
});

Common error messages to watch for:

  • InvalidParameterException: Missing or incorrect parameters (like the typo we fixed earlier)
  • NotAuthorizedException: Invalid/revoked refresh token, or mismatched client ID
  • ResourceNotFoundException: User pool or client ID doesn’t exist (check your Strapi config values)

6. Confirm Strapi Config Values Are Loaded Correctly

It’s easy for config values to be missing or misconfigured. Add a quick log before creating your params to verify:

console.log('Loaded Cognito Config:', {
  ClientId: strapi.config.AWSClientAppId,
  UserPoolId: strapi.config.AWSUserPoolId
});

If either value is undefined or doesn’t match your actual AWS user pool/client ID, that’s the root cause.


内容的提问来源于stack exchange,提问作者rdon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:07:41