I have a single userPool under which I have two client apps.
Using: amazon-cognito-identity-js, aws-sdk
Previously before (Jan 21, 2022 IST), when we signed in using one client app and then used the refresh token api to refresh the access token by passing another client app Id we were getting the error NotAuthorizedException: Invalid Refresh Token.
But since Jan 21, 2022 IST we are receiving a different error for the same scenario - NotAuthorizedException: Refresh Token has different Client.
I also tried with an updated amazon-cognito-identity-js library but the issue persists.
Node.js version: v12.18.4
SDK version number: amazon-cognito-identity-js@1.31.0, aws-sdk@2.177.0
To Reproduce (observed behavior)
Let us consider a userPoolId - UserPoolA
and two client app within the userpool - clientApp1 and clientApp2.
Login using clientApp1.
Use the refresh token received from step (1) to refresh the access token but this time pass the clientId as clientApp2
Initial Error Message: NotAuthorizedException: Invalid Refresh Token (Expected)
New Errror Message: NotAuthorizedException: Refresh Token has different Client (Unexpected, happening since January 21, 2022 IST)
Expected behavior When we signed in using one client app and then used the refresh token api to refresh the access token by passing another client app Id we should be getting the error NotAuthorizedException: Invalid Refresh Token.
Additional context Code Snippet:
// Let us consider a userPoolId - UserPoolA
// and two client app - clientApp1 and clientApp2.
const aws = require(aws-sdk);
const cognitoidentityserviceprovider = new aws.CognitoIdentityServiceProvider();
// For logging in:
const params = {
AuthFlow: "ADMIN_NO_SRP_AUTH"
ClientId: **clientApp1**
UserPoolId: **UserPoolA**
AuthParameters: {
USERNAME: username,
PASSWORD: password
}
}
cognitoidentityserviceprovider.adminInitiateAuth(params, function (err, data) { }
// For refreshing the token:
const params = {
AuthFlow: 'REFRESH_TOKEN_AUTH',
ClientId: **clientApp2** ,
UserPoolId: **UserPoolA**
AuthParameters: {
REFRESH_TOKEN: **refreshToken received from step 1 Login.**
}
}
cognitoidentityserviceprovider.adminInitiateAuth(params, function (err, data) { }
P.S: We hadn't updated any version of the aws package before we started observing this change in message