How to use custom permissions with Cognito

Viewed 624

I am looking for advice on how to store custom permissions in AWS Cognito.

If we store users in Cognito and setup for example 2 groups(roles):

  • admin
  • read-only

And would like to assign some permissions to the group/role:

  • users/create
  • users/delete
  • users/read

So these are available in the token.

Is it possible to do fine grained authorization like this with Cognito or should this be implemented in another way - for example in a database where we query to get the users permissions without using Cognito for this?

Any help is appreciated?

1 Answers

It is certainly possible with Cognito. You can create the 2 groups as you mentioned, admin and read-only. Each group has a separate role associated with them to which you can assign the necessary policies. After this create a cognito identity pool and link your user pool to it. Under Authentication providers make sure to select "Choose Role from Token". For Role resoltion you can choose to either give it a default role or just DENY access.

enter image description here

Related