AWS Amplify集成Azure AD:无法配置urn格式应用ID URI的求助
Amplify集成Entra ID时的SAML标识符冲突问题
我在将应用与Active Directory集成时,先在amplify/auth/resource.ts中添加了以下SAML配置:
externalProviders: { saml: { name: 'MyApp', metadata: { metadataContent: 'https://login.microsoftonline.com/<Tenant ID>/federationmetadata/2007-06/federationmetadata.xml', metadataType: 'URL' }, }, }
接下来我在Azure门户创建应用注册,原本需要修改清单中的identifierUris为以下格式,让Cognito能找到该应用:
"identifierUris": ["urn:amazon:cognito:sp:<region>_<UserPoolID>"]
但现在Entra ID已经不允许这种操作了,报错如下:
根据组织的默认租户策略,所有新添加的URI必须包含租户验证域名、租户ID或应用ID。
现在标识符URI(应用ID URI)只能设置成这种格式:
api://<Application ID>
当我在代码中调用登录方法:
await signInWithRedirect({ provider: { custom: "MyApp" } });
此时收到如下错误:
抱歉,我们无法完成登录。
AADSTS700016: 目录中未找到标识符为'urn:amazon:cognito:sp:region_UserPoolID'的应用
问题在于我找不到修改Amplify中SAML应用标识符的方式——比如想在配置里加一个appIdentifier字段指定自定义的标识符:
externalProviders: { saml: { name: 'MyApp', appIdentifier: 'api://<Application ID>' } }
看起来urn:amazon:cognito:sp:[region]_[UserPoolID]这个标识符是硬编码死的,目前没找到变通方法。有没有人已经解决这个问题了?
内容的提问来源于stack exchange,提问作者Duzmac
相关产品推荐
相关产品推荐

