【问题标题】:AWS Cognito Access Tokens JavascriptAWS Cognito 访问令牌 Javascript
【发布时间】:2020-06-06 22:17:33
【问题描述】:
我正在使用与 Alexa 关联的帐户并取回 accessToken。我正在使用 AWS Cognito 进行身份验证。我的假设是 accessToken 是 AWS Cognito 的令牌 - 但我该如何使用它?我需要获取 CognitoUser 信息。我看过使用 Facebook SDK 的示例,说 Fb.setToken(accessToken) 很简单,但我找不到 Cognito 的等价物。我错过了什么?!
【问题讨论】:
标签:
javascript
amazon-web-services
access-token
amazon-cognito
aws-cognito
【解决方案1】:
我来晚了,但您可以从 URL 获取 AWS Cognito JSON Web 令牌 (JWT) 响应并对其进行解码以获取用户数据:
$( document ).ready(function() {
var pageURL = window.location.href;
pageURL = pageURL.toString();
// Gets url strings
var paramIndex = pageURL.indexOf("#"); // When page is hosted on the web, use '?'
if (paramIndex === -1) {
return;
}
// Gets url parameters from AWS Cognito response including the 'access token'
var parameters = pageURL.substring(paramIndex + 1);
console.log(" page url: " + pageURL);
console.log(" url parameters: " + parameters);
// Extracts the encoded tokens from url parameters
var idToken = getParameter(parameters, "id_token=");
var accessToken = getParameter(parameters, "access_token=");
console.log("id token: " + idToken);
console.log("access token: " + accessToken);
// Decodes the tokens
var idTokenDecoded = atob(idToken.split('.')[1]);
var accessTokenDecoded = atob(accessToken.split('.')[1]);
console.log("id token decoded: " + idTokenDecoded);
console.log("access token decoded: " + accessTokenDecoded);
// Converts string tokens to JSON
var idTokenJson = JSON.parse(idTokenDecoded);
var accessTokenJson = JSON.parse(accessTokenDecoded);
// Can now access the fields as such using the JSON.parse()
console.log("email: " + idTokenJson.email);
console.log("id: " + idTokenJson.sub);
});
/**
* Takes the url parameters and extracts the field that matches the "param"
* input.
* @param {type} url, contains URL parameters
* @param {type} param, field to look for in url
* @returns {unresolved} the param value.
*/
function getParameter(url, param) {
var urlVars = url.split('&');
var returnValue;
for (var i = 0; i < urlVars.length; i++) {
var urlParam = urlVars[i];
// get up to index.
var index = urlParam.toString().indexOf("=");
urlParam = urlParam.substring(0, index + 1);
if (param === urlParam) {
returnValue = urlVars[i].replace(param, "");
i = urlVars.length; // exits for loop
}
}
return returnValue;
}
【解决方案2】:
这是我的身份验证流程,仅使用 cognito,对我来说很好:
var authenticationData = {
Username: document.getElementById("user").value,
Password: document.getElementById("password").value
};
var authenticationDetails = new AmazonCognitoIdentity.AuthenticationDetails(authenticationData);
var poolData = {
UserPoolId: AWSConfiguration.UserPoolId,
ClientId: AWSConfiguration.ClientAppId
};
userPool = new AmazonCognitoIdentity.CognitoUserPool(poolData);
var userData = {
Username: document.getElementById("user").value,
Pool: userPool
};
var cognitoUser = new AmazonCognitoIdentity.CognitoUser(userData);
cognitoUser.authenticateUser(authenticationDetails, {
// authenticate here
【解决方案4】:
AWS Cognito 用户池为身份验证机制生成 id 令牌和访问令牌。它们都是 jwt 令牌,id 令牌具有用户名、电子邮件、姓氏等用户属性。您可以使用 id 或访问令牌对用户进行身份验证。
相关链接:First Link,Second Link