How to customize ID token in AWS Cognito using Pre token generation Lambda trigger?

Поділитися
Вставка
  • Опубліковано 1 січ 2025

КОМЕНТАРІ • 15

  • @securityinaction1018
    @securityinaction1018  Рік тому

    Please subscribe to this channel for regular updates ua-cam.com/channels/EEayyyCrJO94FYlzF0NLTg.html
    Thank You for the support.

  • @AbhishekChaudhary-d2d
    @AbhishekChaudhary-d2d 11 місяців тому

    can we add these two attribute from the attribute present in the cognito user details ??

    • @securityinaction1018
      @securityinaction1018  11 місяців тому

      It would be helpful if you can elaborate the question. Custom attributes will be present in ID token if it is set as readable in the app client attribute permissions. You can refer this documentation for more details docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-attributes.html#user-pool-settings-attribute-permissions-and-scopes

  • @ArgKilljoy
    @ArgKilljoy 7 місяців тому

    Would this be the right approach if I then wanted to map roles from my Azure AD app? (Azure Entra ID)

  • @saahithyanvigneswaran7629
    @saahithyanvigneswaran7629 Рік тому

    Can you do a video on Azure Multi-Tenent with Personal account and AWS Cognito. It seems like cognito doesn't support dynamic issuer which is provided by Azure.

    • @securityinaction1018
      @securityinaction1018  Рік тому +1

      Yes, it is not supported as mentioned in this blog www.thelambdablog.com/azure-ad-multi-tenancy-issue-in-aws-cognito/. It won't work with AzureAD multi-tenant.

  • @AbhishekChaudhary-d2d
    @AbhishekChaudhary-d2d 11 місяців тому

    can we add these two attribute direct from the userpool data custom attribute??

    • @securityinaction1018
      @securityinaction1018  11 місяців тому

      It would be helpful if you can elaborate the question. Custom attributes will be present in ID token if it is set as readable in the app client attribute permissions. You can refer this documentation for more details docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-attributes.html#user-pool-settings-attribute-permissions-and-scopes

  • @juanpablotrujillo6823
    @juanpablotrujillo6823 Рік тому

    Thanks for the video, i've tried to keep the same steps, but my lambda trigger dont invoke, when i generate the token from postman witth domain-cognito/oauth2/token, I don't know if there's any policy missing

    • @securityinaction1018
      @securityinaction1018  Рік тому

      First thing to check is the list of triggers in "User pool properties" tab > Lambda triggers. Next thing to check is the Trigger type "Pre token generation Lambda trigger". If the wrong trigger type is configured, it won't get invoked at the right time. Last thing to check is the policy "Resource based permissions" for the lambda function. I think if you configure the Lambda trigger from AWS console for Cognito user pool, it will automatically add the required permissions.

  • @sergeymanetskiy8201
    @sergeymanetskiy8201 11 місяців тому

    I think it is better to use a good microphone instead of a radio transmitter. Over.

    • @securityinaction1018
      @securityinaction1018  11 місяців тому

      Thanks for the feedback. I will look into this.

    • @medamazigh
      @medamazigh 8 місяців тому +1

      i think it's better to be polite instead of being rude for nothing, no one forced you to watch the video.

    • @sergeymanetskiy8201
      @sergeymanetskiy8201 8 місяців тому

      @@medamazigh I'm not being rude; it's sarcasm. I spent time opening the video only to realize the sound quality is poor. If someone wants their videos to be appreciated, they should work on improving the quality. Otherwise, they should be prepared for various kinds of comments ¯\_(ツ)_/¯