How to attach Cognito Identity ID to the AWS IoT Policy?

Viewed 1079

I am trying to make a connection between AWS IoT and my React JS APP.

I followed this tutorial (https://medium.com/serverlessguru/serverless-real-time-reactjs-app-aws-iot-mqtt-17d023954045), and it is not clear to me how to attach the Cognito Identity ID to the AWS IoT Policy.

During all my investigation, I found that this process must be done through command line.

In the article above, theses process is done by the following command line:

• Note that the “identity_pool_id” has to be considered in this command.

enter image description here

In the aws documentation (https://aws-amplify.github.io/docs/js/pubsub), it says to write the “identity_id” in the command line:

enter image description here

When I use the “identity_pool_id” in the command line, and I try to publish a message from AWS IoT, I got the following error:

enter image description here

When I use the “identity_id” in the command line, I can perform the communication between AWS IoT and the Frontend successfully:

enter image description here

The problem is that the “identity_id” is a different code for each user. Considering that I am going to have a lot of user in my application I don’t know how to perform this task.

• Am I doing the right process to consider the “identity_id” instead of “identity_pool_id”?

• If yes, how could I automatically attach the Cognito ID to the AWS IoT Policy every time I have a new user signedIn in my application?

• Are there any problem to have thousands of Cognito certificates attached in a AWS IoT Policy?

1 Answers

Following answer is in chronological order corresponding to 3 questions.

  1. You can attach only identity_id (user) to IoT policy. Also, I can see you have used "attach-principal-policy" API which is deprecated now, so instead of that please use AttachPolicy API
  2. I'm unsure here, still I'd recommend to evaluate and verify it on Cognito's post confirmation trigger
  3. Absolutely right, you can attach a IoT policy to myriad of certificates; technically it is known as Simplified Permission Management

For #3, Relevant Snippet from AWS (Ref - https://aws.amazon.com/iot-core/faqs/ where find Q. What is Simplified Permission Management?)

"You can share a single generic policy for multiple devices. A generic policy can be shared among the same category of devices instead of creating a unique policy per device. For example, a policy that references the “serial-number” as a variable, can be attached to all the devices of the same model. When devices of the same serial number connect, policy variables will be automatically substituted by their serial-number."

Related