You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iOS中如何将AWS Cognito登录的AuthFlow设为USER_PASSWORD_AUTH

解决AWS Cognito从USER_SRP_AUTH切换到USER_PASSWORD_AUTH的问题

要把登录认证流程从USER_SRP_AUTH改成USER_PASSWORD_AUTH,需要分两步操作:先在AWS控制台开启对应的认证流程,再调整客户端代码的配置(完全不用修改Pods源码),具体步骤如下:

1. 在AWS控制台开启USER_PASSWORD_AUTH认证权限

首先得确保你的Cognito用户池和应用客户端允许使用这个认证方式:

  • 登录AWS控制台,进入你的目标Cognito用户池
  • 切换到App integration标签页,找到App client settings
  • 定位到你的应用客户端,在Auth flows configuration(部分旧版控制台可能叫Allowed OAuth flows)区域,勾选USER_PASSWORD_AUTH选项
  • 保存配置

2. 调整客户端代码的认证流程配置

你不需要动Pods里的代码,只需要在自己的项目代码中指定认证流程类型即可,有两种常用方式:

方式一:通过代码初始化用户池时指定AuthFlow

在初始化AWSCognitoIdentityUserPool的时候,直接配置authFlowType为.userPasswordAuth:

// 替换成你自己的用户池信息
let poolId = "你的用户池ID"
let clientId = "你的应用客户端ID"
let clientSecret = "你的应用客户端密钥(无密钥则传nil)"

let poolConfig = AWSCognitoIdentityUserPoolConfiguration(
    clientId: clientId,
    clientSecret: clientSecret,
    poolId: poolId
)
// 明确指定认证流程为USER_PASSWORD_AUTH
poolConfig.authFlowType = .userPasswordAuth

// 注册并初始化用户池
let userPool = AWSCognitoIdentityUserPool(forKey: "CognitoUserPool", configuration: poolConfig)
AWSCognitoIdentityUserPool.register(userPool, forKey: "CognitoUserPool")

方式二:通过awsconfiguration.json配置

如果你的项目使用awsconfiguration.json管理Cognito配置,直接修改该文件中的AuthFlowType字段:

"CognitoUserPool": {
  "Default": {
    "PoolId": "你的用户池ID",
    "ClientId": "你的应用客户端ID",
    "ClientSecret": "你的应用客户端密钥",
    "Region": "你的AWS区域(比如us-east-1)",
    "AuthFlowType": "USER_PASSWORD_AUTH"
  }
}

3. 保留原有登录代码

完成上述配置后,你原来的登录代码:

passwordAuthenticationCompletion?.set(result: AWSCognitoIdentityPasswordAuthenticationDetails(username: username, password: password))

可以正常使用,此时SDK会自动使用USER_PASSWORD_AUTH流程发起登录请求。

⚠️ 注意:USER_PASSWORD_AUTH会直接传递明文密码(SDK会通过HTTPS传输),但安全性不如USER_SRP_AUTH(SRP会进行密码哈希验证),请根据你的业务场景评估是否适合使用该流程。

内容的提问来源于stack exchange,提问作者Jayprakash Dubey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:20:19