AWS方法级授权如何识别用户身份?Cognito中IAM用户配置问询
Hey there, let's break down your two questions one by one—they’re tied closely to AWS IAM and Cognito’s method-level authorization flow, so I’ll walk you through each clearly.
1. How AWS Method-Level Authorization Distinguishes Regular Users vs. Administrators
It all comes down to permissions context and identity attributes that AWS evaluates when a request hits your API:
- IAM Policies & Roles: The foundational check is the IAM role (and its attached policies) linked to the user’s identity. Administrators will have policies granting broad access—for example,
Allow: *on all API Gateway methods, or explicit permissions for admin-only operations like deleting resources. Regular users get restricted policies, like only allowingGETrequests on user-specific endpoints and no write access. - Cognito User Groups: Most teams use Cognito user groups to segment users. Each group is mapped to an IAM role, so when a user is added to the
Admingroup, they inherit that role’s permissions; regular users inherit their group’s limited role. API Gateway automatically checks this role’s policy when evaluating if a request should be allowed. - Lambda Authorizers (Custom Logic): For more control, you can build a Lambda authorizer. This function inspects the user’s Cognito ID token (looking at claims like
cognito:groupsor custom attributes) and makes a custom allow/deny decision. You can even dynamically generate temporary permissions tailored to the user’s role here.
2. Configuring Cognito to Map IAM Roles to Users for Method-Level Authorization
Note: We don’t assign IAM users directly to Cognito users—instead, we use IAM roles mapped via Cognito user groups or custom attributes. Here are the two most common approaches:
Option 1: Using Cognito User Groups (Recommended for Most Use Cases)
This is the simplest way to segment users into admin/regular roles:
- Step 1: Create IAM Roles for Admins & Regular Users
- Head to the IAM console and create two roles: e.g.,
CognitoAdminRoleandCognitoRegularUserRole. - Attach appropriate policies to each role: grant full API access to the admin role, and restricted access to the regular user role.
- Ensure each role has a trust policy that lets Cognito assume it. Here’s a sample trust policy:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "cognito-identity.amazonaws.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "cognito-identity.amazonaws.com:aud": "YOUR_COGNITO_IDENTITY_POOL_ID" } } } ] }
- Head to the IAM console and create two roles: e.g.,
- Step 2: Create User Groups in Your Cognito User Pool
- Go to the Cognito console, select your user pool, then navigate to
Users and groups > Groups. - Create two groups:
AdminandRegularUser. - For each group, associate the corresponding IAM role (map
CognitoAdminRoletoAdmin,CognitoRegularUserRoletoRegularUser). Set a precedence value (lower number = higher priority if a user is in multiple groups).
- Go to the Cognito console, select your user pool, then navigate to
- Step 3: Assign Users to Groups
- In the
Userstab of your user pool, select a user, clickAdd to group, and assign them to eitherAdminorRegularUser.
- In the
- Step 4: Configure Your Cognito Identity Pool
- Go to the Cognito Identity Pool console, edit your pool, and under
Authentication providers, enableUse role mappingsfor your user pool. - Select
Token contains groupsand map each group to its corresponding role. You can also set a default role for users not in any group.
- Go to the Cognito Identity Pool console, edit your pool, and under
Option 2: Role Mapping Based on Custom User Attributes (For Custom Use Cases)
If you prefer not to use groups, you can map roles based on a custom user attribute (like user_type):
- Step 1: Add a Custom Attribute to Your User Pool
- In your Cognito user pool, add a custom string attribute like
user_type(values can beadminorregular).
- In your Cognito user pool, add a custom string attribute like
- Step 2: Create IAM Roles
- Follow the same steps as Option 1 to create the admin and regular user roles.
- Step 3: Set Up Custom Role Mapping in the Identity Pool
- In the Cognito Identity Pool console, under
Role mapping, selectUse custom roles. - Define rules: e.g., if
user_typeequalsadmin, assignCognitoAdminRole; if it equalsregular, assignCognitoRegularUserRole.
- In the Cognito Identity Pool console, under
- Step 4: Set the Attribute for Users
- When creating or updating users, set their
user_typeattribute to the appropriate value.
- When creating or updating users, set their
How This Powers Method-Level Authorization
When a user logs in via Cognito, they receive an ID token. The Cognito Identity Pool uses this token to determine the correct IAM role, then returns temporary AWS credentials tied to that role. When the user makes a request to your API Gateway, the gateway checks the IAM policy attached to the role to allow or deny the request based on the method and resource.
内容的提问来源于stack exchange,提问作者Ole

