Amplify (JavaScript) - SAML login

Viewed 371

I'm struggling for a few days now with AD SAML login in Amplify.

I've seen a few tutorials but my desired flow is different. I don't have any button which will user click to trigger Auth sequence (and open popup).

Our users are going into a link:

https://....amazoncognito.com/login?response_type=token&client_id=...&redirect_uri=...

Which automatically redirect them into the front-end.

http://localhost:3000/#access_token=...&id_token=...&token_type=Bearer&expires_in=600

Which I can grab the access_token, id_token, token_type and expires_in from the query params.

I can do calls to our back-end with those tokens succesfully..

But what I am struggling with is make Amplify "login" sequence.. so it will identify the user and will create the localStorage values.. so for example when calling Auth.currentSession() it will return the token.

I've tried using Auth.federatedSignIn(..) but to no avail. I am not even sure if it's support this flow or not.

This is what I tried:

Auth.federatedSignIn(
    'test-ad',
    {
        token: idToken,
        expires_at: expiresIn,
    },
    {
        name: "test-user",
    },
);

But I keep getting

Unhandled Rejection (NotAuthorizedException): Invalid login token. Issuer doesn't match providerName

Which is strange as the providerName I'm passing ('test-ad') is the same as I configured in Cognito SAML Provider Name field (in Cognito -> User Pool -> Federation -> Identity Providers -> SAML -> new Provider)

I have my Amplify configured correctly

Amplify.configure({
   Auth: {
      identityPoolId: ...,
      region: ...,
      userPoolId: ...,
      userPoolWebClientId: ...
   }
});

And I can see the Chrome network call is with the correct payload:

{
   "IdentityPoolId":"us-east-x:...",
   "Logins":{
      "test-ad":"...idToken..."
   }
}

so - How can I authenticate into Amplify using token? is it even possible?

Any help will be appreciated!

0 Answers
Related