I'm logging my users via Azure AD using SAML as a federation provider, I wanted to know if it's possible to receive the ip at this point. If so how.
I'm logging my users via Azure AD using SAML as a federation provider, I wanted to know if it's possible to receive the ip at this point. If so how.
I have so far not found a direct way to enable the IP address to be sent to the lambda.
What we know is that the pre-authentication lambda will receive such data, from Cognito:
{
version: '1',
region: '-----------',
userPoolId: '-----------',
userName: '--------------',
callerContext: {
awsSdkVersion: 'aws-sdk-unknown-unknown',
clientId: '----------------'
},
triggerSource: 'PreAuthentication_Authentication',
request: {
userAttributes: {
sub: '-------------',
'cognito:email_alias': '----------------,
'cognito:user_status': 'CONFIRMED',
email_verified: 'true',
email: '--------------------'
},
validationData: {
myCustomPropertiesLikeAnIpAddress: 'anIpAddress'
}
},
response: {}
}
As we can see, the IP address is not contained within. However, we could leverage the "validationData" property, which is a collection of other properties, that can be set from the client.
One such property could be the IP address.
Now we need to somehow obtain this IP address and send it to the lambda.
One way I found to obtain the IP address in a client application, is by making a GET request to https://geolocation-db.com/json/ (or a request to any other IP providers)
The response will look like this
Current IP Address: myIpAddress
Simply clean up the response the way you see fit, then add it to your cognito log in request.
There is a risk for altering the client's code, and not sending, or sending a modified IP address, which, depending on how important this is, you could validate on the lambda itself. You have to see, really, how motivated would somebody be, to do such a modification.