Cognito主要提供两个组件用户池和身份池。
- 用户池:提供应用程序的用户注册和登录功能。
- 身份池:提供用户临时访问AWS服务的临时凭证。
获取用户的临时凭证
aws cognito-idp admin-initiate-auth --user-pool-id us-east-1_8jRRlpLP5 --client-id 66iv5rtllr95kjrh2qokutrnuk --auth-flow ADMIN_NO_SRP_AUTH --auth-parameters USERNAME=ffy,PASSWORD=12345678
获取身份id
aws cognito-identity get-id --identity-pool-id us-east-1:77a07088-99e1-48a3-ace4-16fed91a429b --logins cognito-idp.us-east-1.amazonaws.com/us-east-1_8jRRlpLP5=eyJraWQiOiJcL0dLZHN1OUJxb0dPNTlqQ01LTUpiVlUwMUtKTGNqbHVRQUExSnYybk0zOD0iLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJlNDA4ODRmOC04MGExLTcwNzUtYWViZi1mNzU0NGM0MDVhNjMiLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwiaXNzIjoiaHR0cHM6XC9cL2NvZ25pdG8taWRwLnVzLWVhc3QtMS5hbWF6b25hd3MuY29tXC91cy1lYXN0LTFfOGpSUmxwTFA1IiwiY29nbml0bzp1c2VybmFtZSI6ImN5YyIsIm9yaWdpbl9qdGkiOiIxNWNhMTc4ZC0xZGNjLTQ4ZGEtOTczMy1iZjUyNjYxNTEwNjMiLCJhdWQiOiI2Nml2NXJ0bGxyOTVranJoMnFva3V0cm51ayIsImV2ZW50X2lkIjoiN2M1M2FiZWYtMmQzYi00OTU2LTkxNDktMmJlYzFjYWE4MmVmIiwidG9rZW5fdXNlIjoiaWQiLCJhdXRoX3RpbWUiOjE2OTE1MDI5MjEsImV4cCI6MTY5MTUwNjUyMCwiaWF0IjoxNjkxNTAyOTIxLCJqdGkiOiJlNzdhNmE3Yi1iZDNkLTQwOTktOTI5NC0zOWY0MzYzOTBhMTMiLCJlbWFpbCI6IjE3OTMxNzc1MjNAcXEuY29tIn0.b4jyskxC66t7RYQAbGRcvmcn_zFsVlkPOcP2PlJy8xokCXC2y7Xb4gio7JoFtzznCVAFDIbinUJflTSQ676-STXJdVPemHG8iYJjvWpp7tCTM8VXlpRyPv6G1jCuOJQhz8SbfJgKRqgA7sBqqwc6LJJdGcvqK0oH6jn1cppNyB6wY0UwiiPk1-WQIKokw4wDrggq9echUnbpmhJ-cEL6-AVSiM4kVaUnkUnEttqUB3miA7oqLQOxJ_FohtMKU43cPpP65iMkUaT_sC7CU6Ppb5nEPPmSrdrnr1vTi6CUK3UfcuvYXdgSuY407kvjuIootymIR5o-PR0F-Ms-e6yuDw
检索临时凭证,用户访问权限为经Cognito 身份池验证
aws cognito-identity get-credentials-for-identity --identity-id us-east-1:ee5a8c3a-dcc1-47f4-a403-fb92abfc9511 --logins cognito-idp.us-east-1.amazonaws.com/us-east-1_8jRRlpLP5=eyJraWQiOiJcL0dLZHN1OUJxb0dPNTlqQ01LTUpiVlUwMUtKTGNqbHVRQUExSnYybk0zOD0iLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJlNDA4ODRmOC04MGExLTcwNzUtYWViZi1mNzU0NGM0MDVhNjMiLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwiaXNzIjoiaHR0cHM6XC9cL2NvZ25pdG8taWRwLnVzLWVhc3QtMS5hbWF6b25hd3MuY29tXC91cy1lYXN0LTFfOGpSUmxwTFA1IiwiY29nbml0bzp1c2VybmFtZSI6ImN5YyIsIm9yaWdpbl9qdGkiOiIxNWNhMTc4ZC0xZGNjLTQ4ZGEtOTczMy1iZjUyNjYxNTEwNjMiLCJhdWQiOiI2Nml2NXJ0bGxyOTVranJoMnFva3V0cm51ayIsImV2ZW50X2lkIjoiN2M1M2FiZWYtMmQzYi00OTU2LTkxNDktMmJlYzFjYWE4MmVmIiwidG9rZW5fdXNlIjoiaWQiLCJhdXRoX3RpbWUiOjE2OTE1MDI5MjEsImV4cCI6MTY5MTUwNjUyMCwiaWF0IjoxNjkxNTAyOTIxLCJqdGkiOiJlNzdhNmE3Yi1iZDNkLTQwOTktOTI5NC0zOWY0MzYzOTBhMTMiLCJlbWFpbCI6IjE3OTMxNzc1MjNAcXEuY29tIn0.b4jyskxC66t7RYQAbGRcvmcn_zFsVlkPOcP2PlJy8xokCXC2y7Xb4gio7JoFtzznCVAFDIbinUJflTSQ676-STXJdVPemHG8iYJjvWpp7tCTM8VXlpRyPv6G1jCuOJQhz8SbfJgKRqgA7sBqqwc6LJJdGcvqK0oH6jn1cppNyB6wY0UwiiPk1-WQIKokw4wDrggq9echUnbpmhJ-cEL6-AVSiM4kVaUnkUnEttqUB3miA7oqLQOxJ_FohtMKU43cPpP65iMkUaT_sC7CU6Ppb5nEPPmSrdrnr1vTi6CUK3UfcuvYXdgSuY407kvjuIootymIR5o-PR0F-Ms-e6yuDw
检索临时凭证,用户访问权限为访客
aws cognito-identity get-credentials-for-identity --identity-id us-east-1:77a07088-99e1-48a3-ace4-16fed91a429b