使用JavaScript SDK的AWS Cognito Developer身份验证身份

时间:2016-11-26 08:50:57

标签: javascript amazon-web-services amazon-cognito

我需要使用JavaScript SDK实现Developer Authenticated Identities,但我遇到了问题。我已使用自定义身份验证提供程序配置了标识池

在服务器上:

AWS.config = new AWS.Config({
    region: 'ap-northeast-2',   
    credentials: new AWS.Credentials('XXXXXS7FJBAOO5IXXXXX', 'XXXXXYBo4jmfsu7K0qJSFvu3nlVvYOcVz4GXXXXX')
});

var params = {
    IdentityPoolId: 'ap-northeast-2:a383cb2e-e302-4ff6-8d8f-70e3185XXXXX',
    Logins: {
        'com.abc.xyz': '9876543210' // different value for each user
    }
};

var cognitoidentity = new AWS.CognitoIdentity();
cognitoidentity.getOpenIdTokenForDeveloperIdentity(params, function(err, data) {
    if (err) {
        console.log(err, err.stack); // an error occurred
    }
    else {
        console.log(data);           // successful response
    }
});

服务器结果:

IdentityId: "ap-northeast-2:5cf7f3cd-b370-416b-bed8-f7f8c7aXXXXX"
Token: "eyJra.....sL8bg"

在浏览器上:

AWS.config = new AWS.Config({
    region: 'ap-northeast-2'
});

var params = {
    IdentityId: 'ap-northeast-2:5cf7f3cd-b370-416b-bed8-f7f8c7aXXXXX',      //Received from server
    CustomRoleArn: 'arn:aws:iam::356127965XXX:role/XXXXX_Customer',
    Logins: {
        'com.abc.xyz': '9876543210'
    }
};

var cognitoidentity = new AWS.CognitoIdentity();
cognitoidentity.getCredentialsForIdentity(params, function(err, data) {
    if (err) {
        console.log(err, err.stack); // an error occurred
    }
    else {
        console.log(data);           // successful response
    }
});

浏览器结果:

Please provide a valid public provider

标识池配置 Identity Pool Configuration

2 个答案:

答案 0 :(得分:3)

根据this post,我在浏览器部分进行了以下更改

AWS.config.credentials = new AWS.CognitoIdentityCredentials({
    IdentityId: 'ap-northeast-2:5cf7f3cd-b370-416b-bed8-f7f8c7aXXXXX',      //Received from server
IdentityPoolId: 'ap-northeast-2:a383cb2e-e302-4ff6-8d8f-70e3185XXXXX',
    Logins: {
        'cognito-identity.amazonaws.com': '9876543210'
    }
});

AWS.config.credentials.get(function(err, data) {
    if (err) {
        console.log(err); // an error occurred
    }
    else {
        console.log(data);           // successful response
    }
});

AWS.config.credentials

现在我能够收到包含accessKeyId,expireTime,secretAccessKey和sessionToken

的响应

答案 1 :(得分:1)

我意识到这是一篇过时的文章,但是如果有人遇到了这个问题,我相信如果您进行了更改,您的第一种方法将奏效:

Logins: {
    'com.abc.xyz': '9876543210'
}

收件人

Logins: {
    'cognito-identity.amazonaws.com': "eyJra.....sL8bg"
}

我认为任何不使用您在步骤1)中生成的令牌的解决方案都是不完整的。