I am using AWS Cognito as the central stand-alone authorizer through all services, but I have faced with a couple of issues as below
- no custom scope is added to access token
- practically I can not authorize the resources on ApiGateway by using access token (only id token works which in fact do not help us at all, we strictly need authorization part to be implemented)
- I am trying to use custom flow to try to add custom scopes or claims in pre-token-generation lambda, but I can not find any appropriate incoming event for the lambda or even any code sample on the net
generally, I have not got stuck in only adding scopes, any solution which helps me to implement authorization part which is ACL-like (any user can have any access regarding some conditions or admin decides to grant/revoke specific access permissions to/from specific users)
if nothing works for AWS Cognito I have to switch to another solution which makes me disappointed a lot from AWS Cognito, since I have found this issue reported more than 2 years ago and still not resolved!
and also a lot of time and effort will be wasted from me!
