feat(aws-cognito): users, admin user management and pool-delete parity (C1) - #1378
Merged
Merged
Conversation
| } | ||
|
|
||
| func digest(salt, pw string) string { | ||
| sum := sha256.Sum256([]byte(salt + pw)) |
NitinKumar004
marked this pull request as ready for review
September 27, 2026 16:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
C1 of the Cognito build-out: pool users, the admin user-management calls, AddCustomAttributes, and DeleteUserPool behaving like real Cognito.
What changed
Users (new)
sub. TemporaryPassword is checked against the pool policy, and one is generated when it's left out. MessageAction SUPPRESS is accepted. RESEND re-invites a FORCE_CHANGE_PASSWORD user, and fails with UserNotFoundException for an unknown user or UnsupportedUserStateException for any other state.subcan't be changed. Changing email or phone_number without its_verifiedflag marks it unverified.=and^=on the searchable attributes only), AttributesToGet (null returns everything,[]returns nothing), a Limit of at most 60, and a PaginationToken. It returns "Invalid search attribute: X" and "Error while parsing filter." for bad filters.email_verified=trueon a taken address counts too.AddCustomAttributes (new)
custom:prefix and show up in DescribeUserPool SchemaAttributes. You can passtierorcustom:tier, and names must be 1 to 20 characters. A name that already exists is rejected with "Existing attribute already has name custom:x.", and a pool can have at most 50. Terraform uses this when aschemablock is added to an existingaws_cognito_user_pool, and that update path failed before.DeleteUserPool parity
Other
Schemaentry for a standard attribute, such asemailwithRequired=true, now changes that attribute's Required flag and constraints. Before, the entry was dropped.--persistand snapshot save/load keep them.Tests
{}bodies for TagResource/UntagResource, and check that CloudTrail LookupEvents records CreateUserPool and AdminCreateUser from cognito-idp.amazonaws.com.E2E against
cloudemu servealias_attributesand a standardemailschema block withrequired = true. Apply and plan are clean, and destroy works.email_verifiedflip,custom:t3, the 21-character name, and theemailrequired override. Each one returns the error or result listed above.Not in this PR
Groups and sign-up are C2. Tokens, JWKS and sign-in are C3. The username case-sensitivity setting is not modeled, so usernames are always case-sensitive.
Deferred:
Mutableas false, so honoring it would turnemailimmutable for any SDK caller that leaves the field out. The fix is*boolfor Mutable on the schema wire and driver types (server/aws/cognito/types.go schemaAttributeJSON, services/cognito/driver/types.go SchemaAttribute), and then applying it inoverrideStandard(providers/aws/cognito/user_pools.go).C5 note: the password is stored as
PasswordSaltandPasswordHash(hex salted SHA-256) onuserRecord(providers/aws/cognito/users.go). SRP in C5 needs a verifier derived from the password at set time, so C5 should add a verifier field next to them (and a salt, if SRP's salt differs), filled in by hashPassword's callers: AdminCreateUser, RESEND and AdminSetUserPassword. It should not replace the digest.