aws / aws/aws-sdk-cpp

cognito-idp: "SECRET_HASH was not received" with USER_SRP_AUTH

Đang mở
#3,246 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug needs-reproduction
Ngôn ngữ chính
C++
Star
2.2k
Fork
1.2k
Merge trung bình
4 ngày 11 giờ
Pull request đã merge (30 ngày)
13

Mô tả

### Describe the bug

Hello!
I'm trying to authenticate a user using `CognitoIdentityProviderClient`.

**TL;DR:** Using USER_SRP_AUTH flow and a correct secret_hash, I get a response saying SECRET_HASH was not sent.

Here's the relevant portion of the code:
```
Aws::Map authParameters;
authParameters["USERNAME"] = username.c_str();
// authParameters["PASSWORD"] = password.c_str(); // Used to test with USER_PASSWORD_AUTH below

authParameters["SECRET_HASH"] = "some_secret_hash";
authParameters["SRP_A"] = srp.A();

Aws::CognitoIdentityProvider::CognitoIdentityProviderClient cipClient(clientConfig );

Aws::CognitoIdentityProvider::Model::InitiateAuthRequest authRequest;
authRequest.SetClientId( m_clientID.c_str() );
// authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_PASSWORD_AUTH );
authRequest.SetAuthFlow(Aws::CognitoIdentityProvider::Model::AuthFlowType::USER_SRP_AUTH );

authRequest.SetAuthParameters( authParameters );
Aws::Map __authParameters = authRequest.GetAuthParameters();
// check if the correct value is in the map. It is.

Aws::CognitoIdentityProvider::Model::InitiateAuthOutcome authResult = cipClient.InitiateAuth( authRequest );
```

Then I get: "NotAuthorizedException: Client is configured with secret but SECRET_HASH was not received"

- I have tested all the credentials (user, password, pool Id, app ID, secret_hash, SRP_A, same flow type, etc...) with both Python's `boto3` and `requests` and it works fine both ways (i get tokens and challange).

- Strangely, in the c++ version above:
- Using USER_PASSWORD_AUTH flow instead (and provide a password in the `authParameters`), I don't get the error of "SECRET_HASH was not received"
- Using USER_SRP_AUTH and `authParameters["SECRET_HASH"] = "some_INCORRECT_secret_hash"`, I get an error saying the hash was not correct (but it was, apparently, received)

From what I have read in several StackOverflow that SRP doesn't work with apps with secrets, but those threads seem outdated, and the python test seems to disprove that?

Could you please advise? Is this a limitation of the c++ sdk or is this a bug?

Many thanks in advance!

### Regression Issue

- [ ] Select this option if this issue appears to be a regression.

### Expected Behavior

Expect to receive either a success response or an invalid credentials error, but not a "not sent" error.

### Current Behavior

See description of the bug

### Reproduction Steps

See description of the bug

### Possible Solution

_No response_

### Additional Information/Context

_No response_

### AWS CPP SDK version used

1.11.483

### Compiler and Version used

clang-1600.0.26.6

### Operating System and version

macOS 15.2

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu từ CognitoIdentityProviderClient::InitiateAuth và việc xử lý các tham số xác thực của InitiateAuthRequest, tái hiện USER_SRP_AUTH với SECRET_HASH và so sánh với USER_PASSWORD_AUTH. Kiểm tra xem request đã được serialize có giữ lại SECRET_HASH cho luồng SRP khi sử dụng SDK 1.11.483 trên macOS với clang hay không. Được xem là hoàn tất khi request SRP không còn báo SECRET_HASH bị thiếu và vẫn phân biệt được thông tin xác thực không hợp lệ với hash bị bỏ qua.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
aws, cpp
Lĩnh vực
api, authentication
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
45/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.