feat(aws-cognito): groups, sign-up and password sign-in with RS256 tokens (C2) - #1440
Merged
Merged
Conversation
|
|
||
| rest, ok := strings.CutPrefix(stored, pbkdf2Prefix) | ||
| if !ok { | ||
| sum := sha256.Sum256([]byte(salt + pw)) |
…ser existence, validate token validity
…elivery by pool attribute
NitinKumar004
marked this pull request as ready for review
October 4, 2026 12:16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Cognito C2 from build-out plan A: groups, self sign-up, and password sign-in with real RS256 tokens. This is the first production user of
internal/jwtsign.The plan's C2 row covers groups, sign-up/confirm, the codes endpoint and SECRET_HASH. The token core from C3 is included as well (InitiateAuth, challenges, JWKS, GetUser, sign-out, revoke). Without it, nothing that signs up can sign in. C3 still owns the CloudWatch metrics,
--cognito-issuer-baseand the exportedTokenVerifierfor API Gateway and AppSync.Groups
GroupExistsException.Sign-up
UserSubplus maskedCodeDeliveryDetails(for examplea***@e***). It checks the pool password policy (InvalidPasswordExceptionwith the real message), required schema attributes, sign-in uniqueness, andUsernameExistsException.CodeMismatchException,ExpiredCodeException(codes are 6 digits and last 24h on the clock) andNotAuthorizedExceptionfor a user who is already confirmed. A confirmed user getsemail_verified=true. Also adds ResendConfirmationCode and AdminConfirmSignUp.GET /_cloudemu/cognito/codes?userPoolId=&username=returns the code the emulator would have sent. Under--enforce-authit needs the admin token, like every other admin endpoint.Sign-in and tokens
NotAuthorizedException"Incorrect username or password.";UserNotFoundException, orNotAuthorizedExceptionwhen PreventUserExistenceErrors is ENABLED;UserNotConfirmedException, "User is disabled." andPasswordResetRequiredException.userAttributesandrequiredAttributes.iss=https://cognito-idp.<region>.amazonaws.com/<poolId>,sub,origin_jti,event_id,jti,auth_time,iat,expandcognito:groups(in precedence order).aud,token_use=id,cognito:usernameand the user attributes (email_verifiedas a boolean). It also carriescognito:rolesandcognito:preferred_rolewhen a group has a role.client_id,token_use=access,scope=aws.cognito.signin.user.adminandusername.origin_jtiandauth_timeand does not issue a new refresh token.UnsupportedOperationExceptionwhen token revocation is off, and returnsUnsupportedTokenTypeExceptionfor a non-refresh token.GET /<poolId>/.well-known/jwks.jsonand/openid-configurationare public GETs, and only those exact paths are exempt under--enforce-auth. They register before S3.--persistrestarts. Challenge sessions are not persisted.verifyPasswordmoved from the test file into the package now that sign-in uses it.Tests
.well-knownpaths and POST to the JWKS path still get 403.authbypasscase that expected the JWKS GET to be gated before Cognito served it is removed. The path is public now.E2E (cloudemu serve, port 64366)
--no-sign-request, both in default mode and with--enforce-auth(IAM admin seeded through the admin token): 26/26 checks passed in each mode.--persist: the JWKS is byte-identical, and the access and refresh tokens issued before the restart still work.aws_cognito_user_poolwith a password policy, a client withexplicit_auth_flows,aws_cognito_user_group,aws_cognito_user,aws_cognito_user_in_group): apply, plan clean, sign in as the Terraform user, update the description and flows, plan clean, AdminInitiateAuth on the new flow, destroy. This passed in both modes. Under--enforce-auththe provider block was written out by hand, becausecloudemu-tfpinstest/testcredentials.Review fixes
Deferred
Not in this PR