cognito-idp: "SECRET_HASH was not received" with USER_SRP_AUTH
- Lingua principale
- C++
- Stelle
- 2.2k
- Fork
- 1.2k
- Merge medio
- 3g 14h
- PR unite (30g)
- 12
Descrizione
### Describe the bug
Hello!
I'm trying to authenticate a user using `CognitoIdentityProviderClient`.
**TL;DR:** Using USER_SRP_AUTH flow and a correct secret_hash, I get a response saying SECRET_HASH was not sent.
Here's the relevant portion of the code:
```
Aws::Map authParameters;
authParameters["USERNAME"] = username.c_str();
// authParameters["PASSWORD"] = password.c_str(); // Used to test with USER_PASSWORD_AUTH below
authParameters["SECRET_HASH"] = "some_secret_hash";
authParameters["SRP_A"] = srp.A();
Aws::CognitoIdentityProvider::CognitoIdentityProviderClient cipClient(clientConfig );
Aws::CognitoIdentityProvider::Model::InitiateAuthRequest authRequest;
authRequest.SetClientId( m_clientID.c_str() );
// authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_PASSWORD_AUTH );
authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_SRP_AUTH );
authRequest.SetAuthParameters( authParameters );
Aws::Map __authParameters = authRequest.GetAuthParameters();
// check if the correct value is in the map. It is.
Aws::CognitoIdentityProvider::Model::InitiateAuthOutcome authResult = cipClient.InitiateAuth( authRequest );
```
Then I get: "NotAuthorizedException: Client is configured with secret but SECRET_HASH was not received"
- I have tested all the credentials (user, password, pool Id, app ID, secret_hash, SRP_A, same flow type, etc...) with both Python's `boto3` and `requests` and it works fine both ways (i get tokens and challange).
- Strangely, in the c++ version above:
- Using USER_PASSWORD_AUTH flow instead (and provide a password in the `authParameters`), I don't get the error of "SECRET_HASH was not received"
- Using USER_SRP_AUTH and `authParameters["SECRET_HASH"] = "some_INCORRECT_secret_hash"`, I get an error saying the hash was not correct (but it was, apparently, received)
From what I have read in several StackOverflow that SRP doesn't work with apps with secrets, but those threads seem outdated, and the python test seems to disprove that?
Could you please advise? Is this a limitation of the c++ sdk or is this a bug?
Many thanks in advance!
### Regression Issue
- [ ] Select this option if this issue appears to be a regression.
### Expected Behavior
Expect to receive either a success response or an invalid credentials error, but not a "not sent" error.
### Current Behavior
See description of the bug
### Reproduction Steps
See description of the bug
### Possible Solution
_No response_
### Additional Information/Context
_No response_
### AWS CPP SDK version used
1.11.483
### Compiler and Version used
clang-1600.0.26.6
### Operating System and version
macOS 15.2
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Inizia da CognitoIdentityProviderClient::InitiateAuth e dalla gestione dei parametri di autenticazione di InitiateAuthRequest, riproducendo USER_SRP_AUTH con SECRET_HASH e confrontandolo con USER_PASSWORD_AUTH. Verifica se la richiesta serializzata conserva SECRET_HASH per il flusso SRP usando SDK 1.11.483 su macOS con clang. Il lavoro è completato quando la richiesta SRP non segnala più SECRET_HASH come assente e continua a distinguere tra credenziali non valide e un hash omesso.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- aws, cpp
- Ambito
- api, authentication
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Tranquilla
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 45/100