【问题标题】:AWS Cognito Access Tokens JavascriptAWS Cognito 访问令牌 Javascript
【发布时间】:2020-06-06 22:17:33
【问题描述】:

我正在使用与 Alexa 关联的帐户并取回 accessToken。我正在使用 AWS Cognito 进行身份验证。我的假设是 accessToken 是 AWS Cognito 的令牌 - 但我该如何使用它?我需要获取 CognitoUser 信息。我看过使用 Facebook SDK 的示例,说 Fb.setToken(accessToken) 很简单,但我找不到 Cognito 的等价物。我错过了什么?!

【问题讨论】:

    标签: javascript amazon-web-services access-token amazon-cognito aws-cognito


    【解决方案1】:

    我来晚了,但您可以从 URL 获取 AWS Cognito JSON Web 令牌 (JWT) 响应并对其进行解码以获取用户数据:

    $( document ).ready(function() {
    
    
        var pageURL = window.location.href;
        pageURL = pageURL.toString();
    
        // Gets url strings
        var paramIndex = pageURL.indexOf("#"); // When page is hosted on the web, use '?'
        if (paramIndex === -1) {
            return;
        }
        // Gets url parameters from AWS Cognito response including the 'access token'
        var parameters = pageURL.substring(paramIndex + 1);
    
        console.log(" page url: " + pageURL);
        console.log(" url parameters: " + parameters);
    
        // Extracts the encoded tokens from url parameters
        var idToken = getParameter(parameters, "id_token=");
        var accessToken = getParameter(parameters, "access_token=");
        console.log("id token: " + idToken);
        console.log("access token: " + accessToken);
    
        // Decodes the tokens
        var idTokenDecoded = atob(idToken.split('.')[1]);
        var accessTokenDecoded = atob(accessToken.split('.')[1]);
        console.log("id token decoded: " + idTokenDecoded);
        console.log("access token decoded: " + accessTokenDecoded);
    
        // Converts string tokens to JSON
        var idTokenJson = JSON.parse(idTokenDecoded);
        var accessTokenJson = JSON.parse(accessTokenDecoded);
    
        // Can now access the fields as such using the JSON.parse()
        console.log("email: " + idTokenJson.email);
        console.log("id: " + idTokenJson.sub);
    });
    
    /**
     * Takes the url parameters and extracts the field that matches the "param" 
     * input.
     * @param {type} url, contains URL parameters
     * @param {type} param, field to look for in url
     * @returns {unresolved} the param value.
     */
    function getParameter(url, param) {
        var urlVars = url.split('&');
        var returnValue;
        for (var i = 0; i < urlVars.length; i++) {
            var urlParam = urlVars[i];
    
            // get up to index.
            var index = urlParam.toString().indexOf("=");
            urlParam = urlParam.substring(0, index + 1);
            if (param === urlParam) {
                returnValue = urlVars[i].replace(param, "");
                i = urlVars.length; // exits for loop
            }
        }
        return returnValue;
    }
    

    【讨论】:

    • 我确实有这个视频,可以对上述内容进行更多解释youtu.be/ALgbhPaMT1M 希望对您有所帮助。
    【解决方案2】:

    这是我的身份验证流程,仅使用 cognito,对我来说很好:

      var authenticationData = {
        Username: document.getElementById("user").value,
        Password: document.getElementById("password").value
      };
    
      var authenticationDetails = new AmazonCognitoIdentity.AuthenticationDetails(authenticationData);
    
      var poolData = {
        UserPoolId: AWSConfiguration.UserPoolId,
        ClientId: AWSConfiguration.ClientAppId
      };
    
      userPool = new AmazonCognitoIdentity.CognitoUserPool(poolData);
    
      var userData = {
        Username: document.getElementById("user").value,
        Pool: userPool
      };
    
      var cognitoUser = new AmazonCognitoIdentity.CognitoUser(userData);
    
      cognitoUser.authenticateUser(authenticationDetails, {
    
      // authenticate here
    

    【讨论】:

      【解决方案3】:

      只需在您的 Alexa 技能 Lambda 函数中解码 Cognito 访问令牌。

      https://github.com/awslabs/aws-support-tools/tree/master/Cognito/decode-verify-jwt

      此外,您可以通过使用 Pre Token Generation Lambda 触发器在用户身份验证时向该 jwt 令牌添加属性:

      https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-lambda-pre-token-generation.html

      【讨论】:

        【解决方案4】:

        AWS Cognito 用户池为身份验证机制生成 id 令牌和访问令牌。它们都是 jwt 令牌,id 令牌具有用户名、电子邮件、姓氏等用户属性。您可以使用 id 或访问令牌对用户进行身份验证。

        相关链接:First Link,Second Link

        【讨论】:

          猜你喜欢
          • 2020-10-27
          • 2021-12-21
          • 2020-09-28
          • 2023-04-03
          • 2020-11-20
          • 2016-06-10
          • 2020-04-25
          • 1970-01-01
          • 1970-01-01
          相关资源
          最近更新 更多