aws / aws/aws-sdk-cpp

cognito-idp: "SECRET_HASH was not received" with USER_SRP_AUTH

Open
#3,246 2 comments 0 reactions 0 assignees View on GitHub
bug needs-reproduction
Dominant language
C++
Stars
2.2k
Forks
1.2k
Avg merge
3d 14h
Merged PRs (30d)
12

Description

### Describe the bug

Hello!
I'm trying to authenticate a user using `CognitoIdentityProviderClient`.

**TL;DR:** Using USER_SRP_AUTH flow and a correct secret_hash, I get a response saying SECRET_HASH was not sent.

Here's the relevant portion of the code:
```
Aws::Map authParameters;
authParameters["USERNAME"] = username.c_str();
// authParameters["PASSWORD"] = password.c_str(); // Used to test with USER_PASSWORD_AUTH below

authParameters["SECRET_HASH"] = "some_secret_hash";
authParameters["SRP_A"] = srp.A();

Aws::CognitoIdentityProvider::CognitoIdentityProviderClient cipClient(clientConfig );

Aws::CognitoIdentityProvider::Model::InitiateAuthRequest authRequest;
authRequest.SetClientId( m_clientID.c_str() );
// authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_PASSWORD_AUTH );
authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_SRP_AUTH );

authRequest.SetAuthParameters( authParameters );
Aws::Map __authParameters = authRequest.GetAuthParameters();
// check if the correct value is in the map. It is.

Aws::CognitoIdentityProvider::Model::InitiateAuthOutcome authResult = cipClient.InitiateAuth( authRequest );
```

Then I get: "NotAuthorizedException: Client is configured with secret but SECRET_HASH was not received"

- I have tested all the credentials (user, password, pool Id, app ID, secret_hash, SRP_A, same flow type, etc...) with both Python's `boto3` and `requests` and it works fine both ways (i get tokens and challange).

- Strangely, in the c++ version above:
- Using USER_PASSWORD_AUTH flow instead (and provide a password in the `authParameters`), I don't get the error of "SECRET_HASH was not received"
- Using USER_SRP_AUTH and `authParameters["SECRET_HASH"] = "some_INCORRECT_secret_hash"`, I get an error saying the hash was not correct (but it was, apparently, received)

From what I have read in several StackOverflow that SRP doesn't work with apps with secrets, but those threads seem outdated, and the python test seems to disprove that?

Could you please advise? Is this a limitation of the c++ sdk or is this a bug?

Many thanks in advance!

### Regression Issue

- [ ] Select this option if this issue appears to be a regression.

### Expected Behavior

Expect to receive either a success response or an invalid credentials error, but not a "not sent" error.

### Current Behavior

See description of the bug

### Reproduction Steps

See description of the bug

### Possible Solution

_No response_

### Additional Information/Context

_No response_

### AWS CPP SDK version used

1.11.483

### Compiler and Version used

clang-1600.0.26.6

### Operating System and version

macOS 15.2

Contributor guide

Open the contributing guide

Research direction

Start at CognitoIdentityProviderClient::InitiateAuth and InitiateAuthRequest auth-parameter handling, reproducing USER_SRP_AUTH with SECRET_HASH and comparing it with USER_PASSWORD_AUTH. Check whether the serialized request preserves SECRET_HASH for the SRP flow using SDK 1.11.483 on macOS with clang. Done means the SRP request no longer reports SECRET_HASH as absent and still distinguishes invalid credentials from an omitted hash.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, cpp
Domain
api, authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.