Unable to setup AWS-amplify MFA - issue with the Auth.confirmSignIn function

Viewed 963

I'm having a problem with my adding MFA to my site which manages authentication with AWS Amplify.

I've followed the example here and created the code below to handle both users who have MFA enabled, and those that don't.

const Signin = props => {
const { classes, onStateChange, history } = props;
const [inputs, setInputs] = useState({
    username: '',
    password: '',
});
const [currentStep, setCurrentStep] = useState(1)
const [userObject, setUserObject] = useState({})
const [authCode, setauthCode] = useState({code: ''})

const onSignIn = async (e) => {
    const username = inputs.username.toLowerCase()
    await Auth.signIn({
        username, // Required, the username
        password: inputs.password, // Optional, the password
    }).then(user => {
        if (user.preferredMFA === 'SOFTWARE_TOKEN_MFA'){
            setUserObject(user)
            setCurrentStep(2)}
        else{
            onStateChange('signedIn', {})
            history.push('/dashboard');
        }
    })
        .catch(err => {
            showAlert(err.message)
            if (err.code === 'PasswordResetRequiredException') {
                onStateChange('forgotPassword')
                history.push('/forgotpassword');
            }
        })
}

const MfaSignIn = async (e) => {
    const user=userObject
    await Auth.confirmSignIn(
        user,   
        authCode.code,   
        user.preferredMFA 
    ).then(user => {
        onStateChange('signedIn', {})
    history.push('/dashboard');
    })
    .catch(err => {
        showAlert(err.message)
        if (err.code === 'PasswordResetRequiredException') {
            onStateChange('forgotPassword')
            history.push('/forgotpassword');
        }
    })

If MFA is not enabled the login page will call the onSignIn function then log them in. If MFA is enabled the user object returned from the signin function will return the value "SOFTWARE_TOKEN_MFA" for the preferredMFA key, and a second page will load which allows the user to enter their MFA code, which is handled by the MfaSignIn function.

No MFA works fine, however when attempting to use the MfaSignIn function as is I get "Missing required parameter Session"

the Session key of the user object returned by onSignIn has a value of null, and there's no mention of it needing to be added from the docs. Ive tried adjusting this function to

   const MfaSignIn = async (e) => {
    e.preventDefault(authCode.code);
    const session= Auth.currentSession().then(data=> {return data})
    const token = await session.then(data=>{return data.getAccessToken()})
    const user=userObject
    user.Session=token.jwtToken
    await Auth.confirmSignIn(
        user,   
        authCode.code,   
        user.preferredMFA 
    ).then(user => {
        onStateChange('signedIn', {})
    history.push('/dashboard');
    })
    .catch(err => {
        showAlert(err.message)
        if (err.code === 'PasswordResetRequiredException') {
            onStateChange('forgotPassword')
            history.push('/upgrade');
        }
    })
}

Where I call the Auth.currentSession method and add the data from there to the Session value in the user object. Adding the whole object returns the error-

"Start of structure or map found where not expected." - seems to need a string not a map object

I've tried adding each of the three JWT token strings that are found in the currentSession object, along with the result of the getAccessToken as in the example above. All return the error "Invalid session provided"

I'm at a loss at what I need to give the Auth.confirmSignIn to let the user sign in- I appear to be doing everything correctly as per the docs.

Any ideas?

0 Answers
Related