Class: Aws::CognitoIdentityProvider::Types::InitiateAuthRequest
- Inherits:
-
Struct
- Object
- Struct
- Aws::CognitoIdentityProvider::Types::InitiateAuthRequest
- Defined in:
- gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb
Overview
Initiates the authentication request.
Constant Summary collapse
- SENSITIVE =
[:auth_parameters, :client_id, :user_context_data, :session]
Instance Attribute Summary collapse
-
#analytics_metadata ⇒ Types::AnalyticsMetadataType
Information that supports analytics outcomes with Amazon Pinpoint, including the user's endpoint ID.
-
#auth_flow ⇒ String
The authentication flow that you want to initiate.
-
#auth_parameters ⇒ Hash<String,String>
The authentication parameters.
-
#client_id ⇒ String
The ID of the app client that your user wants to sign in to.
-
#client_metadata ⇒ Hash<String,String>
A map of custom key-value pairs that you can provide as input for any custom workflows that this action triggers.
-
#session ⇒ String
The optional session ID from a
ConfirmSignUpAPI request. -
#user_context_data ⇒ Types::UserContextDataType
Contextual data about your user session like the device fingerprint, IP address, or location.
Instance Attribute Details
#analytics_metadata ⇒ Types::AnalyticsMetadataType
Information that supports analytics outcomes with Amazon Pinpoint, including the user's endpoint ID. The endpoint ID is a destination for Amazon Pinpoint push notifications, for example a device identifier, email address, or phone number.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#auth_flow ⇒ String
The authentication flow that you want to initiate. Each AuthFlow
has linked AuthParameters that you must submit. The following are
some example flows.
- USER_AUTH
The entry point for choice-based authentication with passwords, one-time passwords, and WebAuthn authenticators. Request a preferred authentication type or review available authentication types. From the offered authentication types, select one in a challenge response and then authenticate with that method in an additional challenge response. To activate this setting, your user pool must be in the Essentials tier or higher.
- USER_SRP_AUTH
Username-password authentication with the Secure Remote Password (SRP) protocol. For more information, see Use SRP password verification in custom authentication flow.
- REFRESH_TOKEN_AUTH and REFRESH_TOKEN
Receive new ID and access tokens when you pass a
REFRESH_TOKENparameter with a valid refresh token as the value. For more information, see Using the refresh token.- CUSTOM_AUTH
Custom authentication with Lambda triggers. For more information, see Custom authentication challenge Lambda triggers.
- USER_PASSWORD_AUTH
Client-side username-password authentication with the password sent directly in the request. For more information about client-side and server-side authentication, see SDK authorization models.
ADMIN_USER_PASSWORD_AUTH is a flow type of AdminInitiateAuth and
isn't valid for InitiateAuth. ADMIN_NO_SRP_AUTH is a legacy
server-side username-password flow and isn't valid for
InitiateAuth.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#auth_parameters ⇒ Hash<String,String>
The authentication parameters. These are inputs corresponding to the
AuthFlow that you're invoking.
The following are some authentication flows and their parameters.
Add a SECRET_HASH parameter if your app client has a client
secret. Add DEVICE_KEY if you want to bypass multi-factor
authentication with a remembered device.
- USER_AUTH
USERNAME(required)PREFERRED_CHALLENGE. If you don't provide a value forPREFERRED_CHALLENGE, Amazon Cognito responds with theAvailableChallengesparameter that specifies the available sign-in methods.TARGET_ACR_VALUES. An optional, space-separated list of the authentication context class reference (ACR) level URIs that you want the user to reach. List the levels in priority order, from highest to lowest. Amazon Cognito attempts the highest-priority level that the user can satisfy, and falls back through the list. Amazon Cognito ignores any value that it doesn't recognize. If none of the requested values are valid, Amazon Cognito returns an error.Requesting step-up authentication with this parameter requires the Essentials or Plus feature plan. On a lower feature plan, InitiateAuth returns a FeatureUnavailableInTierException.
USERNAMEis required. When you provide anACCESS_TOKEN, you must also provideTARGET_ACR_VALUES. Amazon Cognito returns an error if you provide anACCESS_TOKENwithoutTARGET_ACR_VALUES. TheUSERNAMEthat you provide must match the user that theACCESS_TOKENwas issued for.For more information about step-up authentication and how Amazon Cognito handles multi-factor authentication requirements, see Step-up authentication with ACR and AMR in the Amazon Cognito Developer Guide.
MAX_AGE. An optional integer that sets the maximum number of seconds allowed since the user last authenticated. If the user's most recent authentication is older than this value, Amazon Cognito discards the authentication-methods credit from any access token that you provide and processes the request as a fresh authentication toward the target level. The access token itself remains valid.
- USER_SRP_AUTH
USERNAME(required)SRP_A(required)
- USER_PASSWORD_AUTH
USERNAME(required)PASSWORD(required)
- REFRESH_TOKEN_AUTH/REFRESH_TOKEN
REFRESH_TOKEN(required)
^
- CUSTOM_AUTH
USERNAME(required)ChallengeName: SRP_A(when doing SRP authentication before custom challenges)SRP_A: (An SRP_A value)(when doing SRP authentication before custom challenges)
For more information about SECRET_HASH, see Computing secret hash
values. For information about DEVICE_KEY, see Working with
user devices in your user pool.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#client_id ⇒ String
The ID of the app client that your user wants to sign in to.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#client_metadata ⇒ Hash<String,String>
A map of custom key-value pairs that you can provide as input for any custom workflows that this action triggers. You create custom workflows by assigning Lambda functions to user pool triggers.
When Amazon Cognito invokes any of these functions, it passes a JSON
payload, which the function receives as input. This payload contains
a clientMetadata attribute that provides the data that you
assigned to the ClientMetadata parameter in your request. In your
function code, you can process the clientMetadata value to enhance
your workflow for your specific needs.
To review the Lambda trigger types that Amazon Cognito invokes at runtime with API requests, see Connecting API actions to Lambda triggers in the Amazon Cognito Developer Guide.
The ClientMetadata value is passed as input to the functions for
only the following triggers:
Pre signup
Pre authentication
User migration
This request also invokes the functions for the following triggers,
but doesn't pass ClientMetadata:
Post authentication
Custom message
Pre token generation
Create auth challenge
Define auth challenge
Custom email sender
Custom SMS sender
ClientMetadata parameter, note that Amazon
Cognito won't do the following:
Store the
ClientMetadatavalue. This data is available only to Lambda triggers that are assigned to a user pool to support custom workflows. If your user pool configuration doesn't include triggers, theClientMetadataparameter serves no purpose.Validate the
ClientMetadatavalue.Encrypt the
ClientMetadatavalue. Don't send sensitive information in this parameter.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#session ⇒ String
The optional session ID from a ConfirmSignUp API request. You can
sign in a user directly from the sign-up process with the
USER_AUTH authentication flow. When you pass the session ID to
InitiateAuth, Amazon Cognito assumes the SMS or email message
one-time verification password from ConfirmSignUp as the primary
authentication factor. You're not required to submit this code a
second time. This option is only valid for users who have confirmed
their sign-up and are signing in for the first time within the
authentication flow session duration of the session ID.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |
#user_context_data ⇒ Types::UserContextDataType
Contextual data about your user session like the device fingerprint, IP address, or location. Amazon Cognito threat protection evaluates the risk of an authentication event based on the context that your app generates and passes to Amazon Cognito when it makes API requests.
For more information, see Collecting data for threat protection in applications.
8090 8091 8092 8093 8094 8095 8096 8097 8098 8099 8100 |
# File 'gems/aws-sdk-cognitoidentityprovider/lib/aws-sdk-cognitoidentityprovider/types.rb', line 8090 class InitiateAuthRequest < Struct.new( :auth_flow, :auth_parameters, :client_metadata, :client_id, :analytics_metadata, :user_context_data, :session) SENSITIVE = [:auth_parameters, :client_id, :user_context_data, :session] include Aws::Structure end |