如何在Python中构造带转义双引号的AWS Cognito命令?
Got it, let's work through that quote escaping issue you're hitting when building the aws cognito-idp list-users command in Python. The shell version uses escaped double quotes (\") around the email, but Python's string handling needs a slightly different approach depending on how you execute the command. Here are the best ways to solve this:
Recommended: Use subprocess with a List of Arguments (No Escaping Needed!)
The safest and cleanest way to run CLI commands in Python is using subprocess.run with a list of arguments. This skips shell interpretation entirely, so you don't need to mess with escaping inner quotes—just pass the filter string exactly as the AWS CLI expects it:
import subprocess # Break the command into a list of individual arguments command = [ "aws", "cognito-idp", "list-users", "--region", "us-west-2", "--user-pool-id", "us-west-2_TEST", "--filter", 'email = "test@test.com"', # No extra escaping needed here! "--query", 'Users[0].Username', "--output", "text" ] # Run the command and capture output result = subprocess.run(command, capture_output=True, text=True) print(result.stdout.strip())
This works because each item in the list is passed directly to the AWS CLI as a separate argument. The filter string 'email = "test@test.com"' is exactly what the CLI needs—no backslashes required.
If You Have to Use shell=True (Not Recommended)
If you're stuck using shell=True (e.g., building a single command string), you need to escape the double quotes twice: once for Python's string parsing, and once for the shell. Here's how to do that:
import subprocess # Build the command string with double-escaped quotes command = '''aws cognito-idp list-users --region "us-west-2" --user-pool-id "us-west-2_TEST" --filter "email = \\"test@test.com\\"" --query 'Users[0].Username' --output text''' # Execute the command (note: shell=True can be risky if inputs are untrusted!) result = subprocess.run(command, shell=True, capture_output=True, text=True) print(result.stdout.strip())
Alternatively, use a raw string to avoid double-escaping backslashes—this makes the string easier to read:
command = r'''aws cognito-idp list-users --region "us-west-2" --user-pool-id "us-west-2_TEST" --filter "email = \"test@test.com\"" --query 'Users[0].Username' --output text'''
Even Better: Ditch the CLI and Use Boto3
Instead of calling the AWS CLI from Python, use the official AWS SDK boto3 to interact with Cognito directly. This eliminates all shell escaping headaches and is way more idiomatic for Python code:
import boto3 # Initialize the Cognito client cognito_client = boto3.client('cognito-idp', region_name='us-west-2') # Fetch the user with the specified email response = cognito_client.list_users( UserPoolId='us-west-2_TEST', Filter='email = "test@test.com"' ) # Extract the username if a user exists if response['Users']: print(response['Users'][0]['Username']) else: print("No user found with that email address.")
This approach is more secure, easier to maintain, and integrates seamlessly with other Python code you might be writing.
内容的提问来源于stack exchange,提问作者Jayesh Dhandha

