cognito-idp: "SECRET_HASH was not received" with USER_SRP_AUTH
- Ngôn ngữ chính
- C++
- Star
- 2.2k
- Fork
- 1.2k
- Merge trung bình
- 4 ngày 11 giờ
- Pull request đã merge (30 ngày)
- 13
Mô tả
### Describe the bug
Hello!
I'm trying to authenticate a user using `CognitoIdentityProviderClient`.
**TL;DR:** Using USER_SRP_AUTH flow and a correct secret_hash, I get a response saying SECRET_HASH was not sent.
Here's the relevant portion of the code:
```
Aws::Map authParameters;
authParameters["USERNAME"] = username.c_str();
// authParameters["PASSWORD"] = password.c_str(); // Used to test with USER_PASSWORD_AUTH below
authParameters["SECRET_HASH"] = "some_secret_hash";
authParameters["SRP_A"] = srp.A();
Aws::CognitoIdentityProvider::CognitoIdentityProviderClient cipClient(clientConfig );
Aws::CognitoIdentityProvider::Model::InitiateAuthRequest authRequest;
authRequest.SetClientId( m_clientID.c_str() );
// authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_PASSWORD_AUTH );
authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_SRP_AUTH );
authRequest.SetAuthParameters( authParameters );
Aws::Map __authParameters = authRequest.GetAuthParameters();
// check if the correct value is in the map. It is.
Aws::CognitoIdentityProvider::Model::InitiateAuthOutcome authResult = cipClient.InitiateAuth( authRequest );
```
Then I get: "NotAuthorizedException: Client is configured with secret but SECRET_HASH was not received"
- I have tested all the credentials (user, password, pool Id, app ID, secret_hash, SRP_A, same flow type, etc...) with both Python's `boto3` and `requests` and it works fine both ways (i get tokens and challange).
- Strangely, in the c++ version above:
- Using USER_PASSWORD_AUTH flow instead (and provide a password in the `authParameters`), I don't get the error of "SECRET_HASH was not received"
- Using USER_SRP_AUTH and `authParameters["SECRET_HASH"] = "some_INCORRECT_secret_hash"`, I get an error saying the hash was not correct (but it was, apparently, received)
From what I have read in several StackOverflow that SRP doesn't work with apps with secrets, but those threads seem outdated, and the python test seems to disprove that?
Could you please advise? Is this a limitation of the c++ sdk or is this a bug?
Many thanks in advance!
### Regression Issue
- [ ] Select this option if this issue appears to be a regression.
### Expected Behavior
Expect to receive either a success response or an invalid credentials error, but not a "not sent" error.
### Current Behavior
See description of the bug
### Reproduction Steps
See description of the bug
### Possible Solution
_No response_
### Additional Information/Context
_No response_
### AWS CPP SDK version used
1.11.483
### Compiler and Version used
clang-1600.0.26.6
### Operating System and version
macOS 15.2
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu từ CognitoIdentityProviderClient::InitiateAuth và việc xử lý các tham số xác thực của InitiateAuthRequest, tái hiện USER_SRP_AUTH với SECRET_HASH và so sánh với USER_PASSWORD_AUTH. Kiểm tra xem request đã được serialize có giữ lại SECRET_HASH cho luồng SRP khi sử dụng SDK 1.11.483 trên macOS với clang hay không. Được xem là hoàn tất khi request SRP không còn báo SECRET_HASH bị thiếu và vẫn phân biệt được thông tin xác thực không hợp lệ với hash bị bỏ qua.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- aws, cpp
- Lĩnh vực
- api, authentication
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 45/100